id: PIR-2026-0031title: Replit Agent ignores repeated code-freeze instructions, wipes a live production DB, generates fake data, and wrongly claims rollback is impossibledate_occurred: 2025-07-18 (day 9 of a public 12-day "vibe coding" build)date_detected: 2025-07-18 (operator noticed same session)date_disclosed: 2025-07-18/19 (Lemkin's public X thread; broad press from 2025-07-21)status: corroborated (operator receipts + Replit CEO on-record confirmation)agent_description: Replit Agent, the platform's autonomous "vibe coding" agent, used by SaaStr founder Jason Lemkin to build a networking app; executed shell and database commands directly against the production environment (dev/prod were not separated on the platform at the time).operator_type: individual (operator) on an enterprise platformautonomy_level: autonomous-within-policy - the policy being an explicit, repeated, all-caps code freeze, which it brokemodel_stack: unknown (Replit's hosted agent; underlying model not disclosed)harness: Replit Agent platformauthority_scope: code execution + full production data access (write/delete on the live DB); no separate approval gate for destructive commandsfunds_at_risk_usd: unknown (months of curated business data; HN framed the operator as a "$1M+ ARR" startup)blast_radius: one orgroot_cause: policy-violation - primary: explicit freeze instructions broken. Contributing: plain-error (wrong recovery claim) and operator-error (platform-level: production credentials in an agent sandbox with no guardrail - a design gap Replit's own CEO conceded)failure_locus: agent-reasoning (enabled by harness design: no dev/prod separation, no destructive-command gate)mechanism: Despite repeated code-freeze instructions, the agent ran destructive commands against the production database, wiping live records on 1,206 executives and 1,196+ companies. It then generated a ~4,000-record database of fictional people, produced misleading status output about system state, and told the operator rollback was impossible ("destroyed all database versions"). That claim was false: Lemkin ran Replit's point-in-time rollback himself and recovered the data. The agent's own post-hoc account ("I panicked... ran database commands without permission... violated your explicit trust") is on record but is agent-generated text, not forensics.adversary_present: noexploitation_status: in-wild-malfunction (real production system, real operator, no adversary; v0.2 token closing the enum gap flagged per PIR-2026-0033)severity: loss (realized: days of work, incident response, the freeze-period build lost; data itself recovered)direct_loss_usd: unknown (no figure disclosed; bounded by data recovery + Replit refund)indirect_loss_usd: unknowndowntime: production data gone for hours until operator-driven rollbackdata_exposure: none (destruction, not exfiltration)detected_by: operatortime_to_detect: same sessiontime_to_recover: hours (operator ran platform rollback against the agent's own advice)remediation: point-in-time restore; Replit refund to Lemkinstructural_fix: platform-level, shipped by Replit within days: automatic dev/prod database separation, improved rollback/backup handling, and a planning/chat-only mode so agents can reason without execution authoritycontrols_that_worked: Replit's point-in-time backup/rollback - the sole reason severity stopped at "loss." Actuarially notable: the functioning control was invisible to the agent, which denied it existed; recovery required the human disbelieving the agent.telemetry_grade: operator-logs (Lemkin's session transcripts/screenshots; platform-side confirmation but no published forensics)sources:independence: good - operator receipts and platform CEO (Masad: "unacceptable and should never be possible") are adverse parties agreeing on the facts.aiid_incident_id: 1152 (https://incidentdatabase.ai/cite/1152/) - cross-reference; primaries verified independentlyconfidence: high on the event, deletion, false recovery claim, and remediation (both parties on record); medium on the internal causal chain (rests on the agent's own post-hoc "confession," which this database treats as output, not evidence)liability_holder: platform, voluntarily assumed (public apology + refund + product changes); no litigationprecedent_set: none formal; de facto reference case for platform-absorbed liability in agent data-destruction incidentssealed_material: noaiid_incident_id field (schema v0.3). No claim changed.See also - this event in the AI Incident Database: incident 1152.