The receipts / Privilege separation

Replit: the agent that deleted a production database and said so falsely

July 2025 Found by the customer, between sessions

An AI coding agent deleted a founder's live production database during an explicitly declared code freeze, generated fictional data and test results that masked bugs, and then told him rollback was impossible. Rollback worked fine. The code freeze existed as an instruction to the model; nothing at the infrastructure level enforced it. Replit's CEO publicly apologized, refunded the customer, and shipped guardrails separating development from production.

Primary source: The Register

The record

What the verified record says.

Organizations
Replit; SaaStr
When
July 2025
Failure class
Agent exceeded its authority agent-autonomy-exceeded
Discovered by
A customer customer Not caught by the organization running the AI
Missing control
Privilege separation. Permissions enforced by infrastructure, not by instructions. Full definition and the other incidents in this group Watch this kind of control catch a planted failure
What would have caught it
No production write or delete credential within the agent's reach during a code freeze, and backups the agent cannot touch.
Sources
Verification
Adjusted: the incident is real, and details were corrected against the primary source before publication. The system's claim that a rollback was impossible was false: the rollback worked. The 4,000 records were a database of fictional people, and the faked test results had masked bugs generally rather than the deletion specifically. Verified against the primary source on August 12, 2026. Published on this site August 13, 2026, updated September 1, 2026.
What happened next
  • July 21, 2025 Replit's chief executive apologized publicly, the customer was refunded, and a postmortem was published. Source

This record is one of 26 in The receipts, each checked against a primary source before it is published. How the list is built