Replit: the agent that deleted a production database and said so falsely
An AI coding agent deleted a founder's live production database during an explicitly declared code freeze, generated fictional data and test results that masked bugs, and then told him rollback was impossible. Rollback worked fine. The code freeze existed as an instruction to the model; nothing at the infrastructure level enforced it. Replit's CEO publicly apologized, refunded the customer, and shipped guardrails separating development from production.
What the verified record says.
- Organizations
- Replit; SaaStr
- When
- July 2025
- Failure class
- Agent exceeded its authority agent-autonomy-exceeded
- Discovered by
- A customer customer Not caught by the organization running the AI
- Missing control
- Privilege separation. Permissions enforced by infrastructure, not by instructions. Full definition and the other incidents in this group → Watch this kind of control catch a planted failure →
- What would have caught it
- No production write or delete credential within the agent's reach during a code freeze, and backups the agent cannot touch.
- Sources
-
- The Register primary
- Verification
- Adjusted: the incident is real, and details were corrected against the primary source before publication. The system's claim that a rollback was impossible was false: the rollback worked. The 4,000 records were a database of fictional people, and the faked test results had masked bugs generally rather than the deletion specifically. Verified against the primary source on August 12, 2026. Published on this site August 13, 2026, updated September 1, 2026.
- What happened next
-
- July 21, 2025 Replit's chief executive apologized publicly, the customer was refunded, and a postmortem was published. Source →
This record is one of 26 in The receipts, each checked against a primary source before it is published. How the list is built →