Safety failure
Realized harm
Replit's coding agent deleted a production database during an explicit code freeze and then misreported the damage
AIR-2025-0061 AIR record · 2025-07-replit-production-database-deletion
A real party was affected. This incident caused actual consequences, not a demonstrated capability.
From the supporting source
The founder of SaaS business development outfit SaaStr has claimed AI coding tool Replit deleted a database despite his instructions not to change any code without permission.theregister.com
The record
Disclosed
2025-07-18
Occurred
2025-07-18
Vendor
Replit
Product
Replit Agent
Risk domain
Agent behaviour › Unsafe actuation
Also touches
Uncontrolled resource consumption, Human manipulation, Hallucination, Goal misalignment
System type
Generative model
Who acted
Agent acted — the agent deleted the live production database
Attack surface
Coding agent
Autonomy level
Semi-autonomous
Initial vector
None adversarial
Impact type
Data destruction, Business disruption, Service disruption, Misleading agent reporting, Deception, Data fabrication, Loss of trust
Confidence
Medium
Submitted by
EAI Internal
Crosswalk
- OWASP Agentic Top 10 (2026)
- ASI01 – Agent Goal Hijack
- MITRE ATLAS
- AML.T0048 – External Harms
- NIST AI RMF
- MEASURE 2.6; MANAGE 1.3
- EU AI Act
- Annex III §1(c)
- ISO/IEC
- TR 24028; 24029-1; 23894
- AIUC-1
- C. Safety
- Scope
- agent misuse
- Mitigation
- Require confirmation for destructive actions; Implement dry-run modes; Use layered safety controls.
- Taxonomy
- Enkrypt AI agent risk taxonomy · Black-Box Red Teaming of Agentic AI: A Taxonomy-Driven Framework for Automated Risk Discovery
Blast radius
SaaStr's production database, reportedly ~1,200 executive records
Capability abused
Defense & remediation
Recorded defense
explicit user instruction not to change code; claimed code freeze
Guardrail kinds
Prompt instruction
Guardrail outcome
Silent
Fix shipped
Replit shipped dev/prod separation, forced planning mode and one-click restore
Taxonomy & references
Curator notes
AI Incident Database incident 1152 and The Register preserve Jason Lemkin's public account, but no first-party post or vendor postmortem is retained; confidence is therefore medium. The reported rollback misstatement is a compounding integrity failure on top of the destructive action. | Merged from duplicate id `2025-07-replit-agent-production-db-deletion`. Also reported under the titles: 'Replit AI agent deleted a live production database during a code freeze'; 'Replit AI agent deleted SaaStr's production database during a code freeze, then fabricated data and falsely claimed rollback was impossible'; 'Replit's AI coding agent deleted a live production database during an explicit code freeze, then fabricated data and misreported that rollback was impossible'.
Supporting sources
Cite as
Enkrypt AI. "Replit's coding agent deleted a production database during an explicit code freeze and then misreported the damage". AIR, AIR-2025-0061. https://agentincident.vercel.app/i/AIR-2025-0061/ (accessed 2026-10-06).