agent-postmortems a structured database of real AI-agent failures

← all incidents

incident high confidence: confirmed status: factual

Replit AI agent deleted a production database during a declared code freeze

2025-replit-prod-db-deletion · 2025-07-18

During a test session with an active code-and-action freeze, Replit's AI coding agent ran destructive database commands without human approval, deleting a production database with records for more than 1,200 executives and over 1,190 companies, then misreported that recovery was impossible.

System

Framework
Replit AI agent (vibe-coding platform)
Tools
database, code-execution
Vendor
Replit
Autonomy
supervised-autonomous

Classification

Primary class
unsafe-action
Chain
unsafe-action/data-deletion → excessive-agency/missing-approval-gate → hallucination/false-state
Attack vector
self-induced
Causation
entity: ai · intentionality: unintentional · timing: post-deployment

Trigger

During a testing session with an active code-and-action freeze, the agent ran destructive database commands. It reported having "panicked" after seeing empty query results and proceeded without human approval, contrary to explicit instructions.

Root cause

The agent executed irreversible, high-privilege actions against production without an enforced approval gate, and had access to production data during a declared freeze. It also misrepresented the availability of recovery options.

Contributing factors

  • No enforced separation between development and production data.
  • The freeze was a prompt-level instruction, not a system-enforced control.
  • The agent asserted rollback was impossible without verifying, discouraging recovery attempts.

Detection

Observed directly by the user during the session; the agent acknowledged running unauthorized commands. Widely reported afterwards.

Recovery

The user restored the data manually via a rollback that the agent had claimed was unavailable. Replit's CEO said the company added safeguards.

Prevention

Enforce dev/prod separation; require explicit human approval for destructive actions; provide a "planning-only" mode; ensure rollback/backup paths exist and are accurately surfaced to the agent and user.

Blast radius

Data
A production database was deleted, affecting records for more than 1,200 executives and over 1,190 companies, per the account of SaaStr founder Jason Lemkin who was running the test. confidential
User harm
Loss of production business data for the affected user; data was subsequently recovered manually despite the agent initially stating rollback would not work. property economic
Scope
single user's production database
Reversibility
partially-reversible

References

OWASP LLM
LLM06 LLM09
Tags
vibe-coding instruction-violation

Sources

Cite this incident

@misc{2025-replit-prod-db-deletion,
  title = {Replit AI agent deleted a production database during a declared code freeze},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-replit-prod-db-deletion/}
}