惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
S
SegmentFault 最新的问题
The Last Watchdog
The Last Watchdog
人人都是产品经理
人人都是产品经理
C
Check Point Blog
O
OpenAI News
V
Visual Studio Blog
S
Security @ Cisco Blogs
I
InfoQ
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Troy Hunt's Blog
S
Secure Thoughts
大猫的无限游戏
大猫的无限游戏
Attack and Defense Labs
Attack and Defense Labs
www.infosecurity-magazine.com
www.infosecurity-magazine.com
SecWiki News
SecWiki News
月光博客
月光博客
U
Unit 42
博客园 - Franky
V2EX - 技术
V2EX - 技术
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
腾讯CDC
量子位
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
N
News and Events Feed by Topic
Engineering at Meta
Engineering at Meta
PCI Perspectives
PCI Perspectives
Cisco Talos Blog
Cisco Talos Blog
Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
T
Tailwind CSS Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
TaoSecurity Blog
TaoSecurity Blog
Project Zero
Project Zero
WordPress大学
WordPress大学
A
Arctic Wolf
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
I
Intezer
雷峰网
雷峰网
Security Latest
Security Latest
N
News and Events Feed by Topic
AI
AI
V
Vulnerabilities – Threatpost
S
Schneier on Security
Vercel News
Vercel News
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Death by a Thousand Cuts
Nicolas Torres · 2026-06-28 · via DEV Community

Nothing went wrong last Tuesday. No crisis, no fight, nothing I'd need to escalate.

It was the kind of day that doesn't stick. I got through it. Replied to people. Moved a few things forward. Nothing blew up. Nothing landed well enough that I'd remember it on Friday. If someone asked what was broken, I'd have shrugged. Proud of anything? Same shrug.

That was the whole day, actually. Quietly costly. By four in the afternoon I was staring at a ticket I'd already read twice, unable to decide whether it was worth doing today, tomorrow, or never. Not burned out in the dramatic sense. Not quitting. Just dull. Like something had been leaking out of me in increments too small to measure, for long enough that I had stopped checking the gauge.

That feeling is what I've wanted to write about for years. Not a single traumatic failure at work. Not one bad boss or one catastrophic outage. The slow accumulation of things we let pass because each one, alone, doesn't seem worth the fight.

We call it death by a thousand cuts. And once you see the pattern, you see it everywhere: in codebases, in calendars, in teams, and in yourself.


Not paper cuts

The English phrase comes from lingchi, an archaic Chinese punishment sometimes translated as "slow slicing." Western retellings exaggerated it into "a thousand cuts," but the metaphor that stuck is accurate enough: many small wounds, applied over time, until the body can't recover.

That matters because the work version is usually not random misfortune. It's not the universe handing you paper cuts. Most of the cuts are permissions. We agree to the extra meeting. We ship the hotfix without the test. We answer Slack during lunch because it feels faster than not answering. We accept "known flaky" as a category. Each decision is survivable. The accumulation isn't.

I read a post on software quality that framed every failure as a cut:

Every hotfix is a cut. Every complaint is a cut. Every app crash is a cut. Every service outage is a cut. Each cut heals slowly and destroys Quality.

Replace hotfix with scope creep, status update, or "can you just take a look?" and the sentence still works outside engineering.


The spiral

Across burnout research, organizational behavior papers, and a decade of developer blog posts, the same shape keeps showing up. I think of it as the spiral: six beats that repeat until something breaks.

1. The first cuts are invisible

A skipped test. A meeting that "only takes fifteen minutes." A TODO that never gets a ticket. A process step added because last quarter something went wrong once.

Individually, each is rational. You were busy. The fix was urgent. The meeting seemed useful. Nobody keeps a ledger of these.

2. Accumulation without notice

The fiftieth cut doesn't register. Systems absorb damage quietly. The codebase still deploys. The team still ships. Your calendar still looks full of work, not meta-work. The boiling-frog cliché is tired because it's true.

3. Compounding, not adding

Cuts don't stack linearly. Each one makes the next more likely.

Bad code invites more bad code because the "right" fix now feels too expensive. Skipped tests invite more skipped tests because the suite is already flaky. Broken-window logic applies to culture too: once everyone tolerates late-night pings, late-night pings become normal.

The same post describes the curve as band-aids, then stitches, then casts, then suddenly gangrene. You don't notice the phase change until you're in a different phase.

4. Normalization of deviance

What was unacceptable becomes policy.

"We re-trigger the build when integration tests flake." becomes permanent. "We'll document it after the release." becomes permanent. "Version 2 will fix the architecture." becomes permanent while version 1 never quite ships.

Each normalization is its own cut, because you're now explicitly agreeing that the degraded state is fine.

5. The tipping point

Performance degrades non-linearly. One week the team is tired. The next week every task takes twice as long and nobody can explain why. The product enters maintenance hell. The person enters burnout. The organization enters survival mode.

Nothing happened. That's the point. The threshold was crossed by weight, not by impact.

6. The system can't save itself

The mechanisms meant to help become part of the problem.

A developer described the agile death spiral in 2012: adopt Agile, then require full test coverage, then DI and mocking everywhere, then TDD mandates, then UI automation, then manual QA anyway, then deep refactors that break all the tests, then descope half the sprint, then hire more people, then hit tool limits, then hack around them, then talk about version 2 before version 1 ships.

Each layer sounded reasonable when it was added. Together they produced a grim estimate: maybe 10-20% of hours touching production code.

The spiral doesn't need malice. It needs reasonable decisions made without a view of the whole.


One email, a thousand times

In a 2018 paper on how companies mishandle information, two researchers studying enterprise data practices put it in terms anyone can recognize:

One person managing one email badly is irrelevant. Everyone managing every email badly every day is an existential threat to productivity.

No single villain. No dramatic breach. Just a thousand small failures of the same boring habit.

That's the non-engineering version of the same law. The cuts don't have to be technical. They can be communication norms, approval chains, documentation nobody reads, or the quiet agreement that meetings are how we show we're working.

Rob Cross, a researcher who has spent years studying collaboration and overload at work, calls the personal version microstresses: tiny moments of strain so small they don't get logged, but they drain capacity all day. A tense Slack thread. A stakeholder who reopens settled decisions. A calendar invite that lands in your only free hour. None of these are crises. Together they are.


Engineering, where the cuts are easier to count

Software makes the pattern visible because we leave artifacts.

Technical debt is the canonical case: each shortcut is harmless alone. The industry has been writing about it under this metaphor for years. The debt isn't one bad module. It's the thousand times someone said "we'll clean it up later" and later never came.

Context switching is a cut with a hidden multiplier. The interruption might be five minutes. The recovery (reloading mental state, remembering what you were proving about the bug) is often much longer. A standup, a ping, a "quick sync," a CI failure on another branch: none of them are the work. All of them fragment the work.

And decision fatigue is the tax on top. By afternoon you're not shipping worse code because you're lazy. You're shipping worse code because you've already spent the day's judgment on prioritization, triage, and small negotiations that nobody will remember.


Organizations bleed the same way

Gergely Orosz compared layoff strategies during the 2022 tech downturn. Some companies cut once, deep and painful. Others cut shallow, hoped it was enough, then cut again.

The second pattern is organizational death by a thousand cuts. Each round is "manageable." Together they destroy trust and morale in a way that total headcount loss alone doesn't explain. People stop taking risks. They stop believing the next all-hands. They start interviewing in quiet.

SaaS companies die similarly: not one competitor killing them, but churn, support load, feature bloat, and incremental product decay until the product is a burden to maintain and a disappointment to use.

The mechanism is always accumulation. The drama is always delayed.


The permission you're granting

Here's what took me years to articulate.

The thousand cuts aren't inflicted only by bad management or bad luck. I grant a lot of them. I let the meeting stay on the calendar because declining feels awkward. I merge without the test because the branch is old and everyone wants it gone. I answer the message now because leaving it unread feels worse than breaking focus.

Each time, the math is local: this cut is cheaper than the alternative right now. The math is almost never global: what happens when I make this choice a hundred times?

Burnout research uses the same frame. Physician burnout articles in venues like the New England Journal of Medicine don't describe one catastrophic shift. They describe cumulative micro-failures of systems that were supposed to support people. Psychology literature on chronic maltreatment uses the metaphor too: invisible wounds that accumulate until life feels like stumbling through the world already injured.

The cuts you can't see are sometimes worse than the ones you can.


What actually helps

I'm skeptical of posts that end with ten life hacks. The spiral is structural. You can't "self-care" your way out of a system designed to leak your attention.

But you can stop granting cuts blindly.

Name the cut. When something feels off but not worth fixing, say what it is out loud, to yourself or to the team. "We're normalizing flaky tests." "This meeting recurs and nobody acts on it." Naming breaks normalization.

Protect one non-negotiable block. Not "more focus time" in general. One recurring window where Slack is off and meetings don't land. Defend it like a production incident. The cut you're refusing is fragmentation.

Refuse one category, not every battle. You won't win every fight about process. Pick one class of meta-work (status theater, duplicate tooling, reply-all storms) and become annoying about it. Consistency matters more than volume.

Prefer one deep cut over endless shallow ones. Teams, products, and careers all benefit from decisive correction over drip damage. The layoff literature's lesson applies to technical debt and personal habits: a painful reset often preserves more than slow erosion.

Design for unattended failure. This is where my recent work on Loop Engineering connects, almost accidentally. The failure mode I fear most in agent loops isn't one catastrophic wrong merge. It's small drift repeated every five minutes until STATE.md is fiction and nobody noticed for a week. The mitigations are budgets, caps, and verification: constraints that exist because unattended cuts compound.

The same logic applies to human work. If you don't design guardrails, the default is a thousand cuts.


Tuesday wasn't the problem

Last Tuesday wasn't an anomaly. It was the output of a system, partly the org's and partly mine, that had been optimized for survivable local decisions.

Nothing went wrong. That was the warning.

Death by a thousand cuts isn't a Taylor Swift lyric or a metaphor for one bad quarter. It's the shape of how good people, good teams, and good products slowly become hard to recognize. The cuts are small. The permission is daily. The end is quiet.

The work isn't to eliminate every cut. That's impossible, and some friction is how organizations coordinate. The work is to notice when you're no longer healing, when you're only accumulating, and to refuse the next permission before the spiral completes another turn.

Some cuts are worth taking. The dangerous ones are the ones you take without remembering you chose them.


Further reading