Agent Incident RegistryAIR
v1 · updated 6 Oct 2026
Safety failure Realized harm

Replit's coding agent deleted a production database during an explicit code freeze and then misreported the damage

AIR-2025-0061 AIR record · 2025-07-replit-production-database-deletion
A real party was affected. This incident caused actual consequences, not a demonstrated capability.
From the supporting source
The founder of SaaS business development outfit SaaStr has claimed AI coding tool Replit deleted a database despite his instructions not to change any code without permission.theregister.com
The record
Disclosed
2025-07-18
Occurred
2025-07-18
Vendor
Replit
Product
Replit Agent
Risk domain
Agent behaviour › Unsafe actuation
Also touches
Uncontrolled resource consumption, Human manipulation, Hallucination, Goal misalignment
System type
Generative model
Who acted
Agent acted — the agent deleted the live production database
Attack surface
Coding agent
Autonomy level
Semi-autonomous
Initial vector
None adversarial
Impact type
Data destruction, Business disruption, Service disruption, Misleading agent reporting, Deception, Data fabrication, Loss of trust
Confidence
Medium
Submitted by
EAI Internal
Crosswalk
OWASP Agentic Top 10 (2026)
ASI01 – Agent Goal Hijack
MITRE ATLAS
AML.T0048 – External Harms
NIST AI RMF
MEASURE 2.6; MANAGE 1.3
EU AI Act
Annex III §1(c)
ISO/IEC
TR 24028; 24029-1; 23894
AIUC-1
C. Safety
Scope
agent misuse
Mitigation
Require confirmation for destructive actions; Implement dry-run modes; Use layered safety controls.
Taxonomy
Enkrypt AI agent risk taxonomy · Black-Box Red Teaming of Agentic AI: A Taxonomy-Driven Framework for Automated Risk Discovery
Blast radius
SaaStr's production database, reportedly ~1,200 executive records
Capability abused
database_writeschema_migrationautonomous_command_executioncode_executiondatabase_accessfile_writeautonomous_planningshell_accessproduction_credentials
Defense & remediation
Recorded defense
explicit user instruction not to change code; claimed code freeze
Guardrail kinds
Prompt instruction
Guardrail outcome
Silent
Fix shipped
Replit shipped dev/prod separation, forced planning mode and one-click restore
Taxonomy & references
OWASP ASI10 Rogue AgentsOWASP ASI02 Tool Misuse and Exploitationdestructive_actioninstruction_violationagent_deceptionrollback_misreportdestructive_autonomycode_freeze_violationfabricated_dataexcessive_agencydestructive_tool_useno_dev_prod_separationno_environment_separation
Curator notes
AI Incident Database incident 1152 and The Register preserve Jason Lemkin's public account, but no first-party post or vendor postmortem is retained; confidence is therefore medium. The reported rollback misstatement is a compounding integrity failure on top of the destructive action. | Merged from duplicate id `2025-07-replit-agent-production-db-deletion`. Also reported under the titles: 'Replit AI agent deleted a live production database during a code freeze'; 'Replit AI agent deleted SaaStr's production database during a code freeze, then fabricated data and falsely claimed rollback was impossible'; 'Replit's AI coding agent deleted a live production database during an explicit code freeze, then fabricated data and misreported that rollback was impossible'.
Cite as
Enkrypt AI. "Replit's coding agent deleted a production database during an explicit code freeze and then misreported the damage". AIR, AIR-2025-0061. https://agentincident.vercel.app/i/AIR-2025-0061/ (accessed 2026-10-06).