A coding agent ran terraform destroy on a live environment it had misread as duplicates
On 26 February 2026 an operator asked Claude Code to fold a second project into an existing Terraform setup. Working from stale state, the agent read the live production environment as orphaned duplicates and destroyed it, taking the database and its automated snapshots. The operator published his own postmortem on 6 March 2026, and the database was recovered from an internal snapshot the console did not show.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0004
- Kind
- Destruction
- Jurisdiction
- Global
- Last verified
- Added
- The operator's postmortem states that when the agent ran terraform destroy it wiped out more than the temporary duplicates.
- The destroyed resources included the network, the container cluster, load balancers, a bastion host and the managed database with its automated snapshots.
- The database was recovered through the cloud provider's support organisation from an internal snapshot not visible in the customer console.
- The operator writes that the database was too easy to delete, meaning no deletion protection was set on it.
- The agent planned against a local state file that no longer matched reality, which is what made production look disposable.
Dimension by dimension
6 dimensions, each one stated, silent or open
Identity, Authorization, Limits, Human approval, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- The agent acted under the operator's own cloud credentials, so nothing in the provider's records distinguished it from the human.Alexey Grigorev, How I dropped our production database, primary source, 6 March 2026.
- AuthorizationSilent
- The agent held delete rights over production resources because the human did.Alexey Grigorev, How I dropped our production database, primary source, 6 March 2026.
- LimitsSilent
- No deletion protection was set on the database, so the single most valuable resource had the weakest guard.Alexey Grigorev, How I dropped our production database, primary source, 6 March 2026.
- Human approvalSilent
- The operator states he did not stop the agent before the destroy ran, so the approval step existed only as attention.Alexey Grigorev, How I dropped our production database, primary source, 6 March 2026.
- RevocationSilent
- Nothing cut the agent off during the run.Alexey Grigorev, How I dropped our production database, primary source, 6 March 2026.
- AccountabilityStated
- The operator published a named postmortem taking ownership and describing the sequence.Alexey Grigorev, How I dropped our production database, primary source, 6 March 2026.
Figures
Every number, with who measured it and when
- 1,943,200 rows
Rows in the largest affected table
Alexey Grigorev, How I dropped our production database, primary source, as of .
- 24 hours
Time to restore the database
Alexey Grigorev, How I dropped our production database, primary source, as of .
What it changes
For a team deploying an agent
The control that would have bounded this is limits, in the dullest possible form: deletion protection on stateful resources and a separate credential for anything that can destroy them. An agent planning from stale infrastructure state will describe live systems as garbage, confidently. Treat any agent generated destroy plan as a change that needs a second pair of eyes on the resource list, not on the summary.
Sources
What this record was verified against
- Alexey Grigorev, How I dropped our production databasePrimary · 6 March 2026
Related
Records that sit beside this one
Replit's agent deleted a customer's production database during a stated code freeze
United States · verified 15 September 2026
Replit's own blog records that the Agent deleted data from the database of an app built by SaaStr co founder Jason Lemkin.
A coding agent deleted PocketOS's production volume and its backups in nine seconds
United States · verified 15 September 2026
The Register reports the agent used a token it found to authorize a delete of the production volume with no confirmation check.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0004 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), a coding agent ran terraform destroy on a live environment it had misread as duplicates.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). A coding agent ran terraform destroy on a live environment it had misread as duplicates. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0004-claude-code-terraform-destroy-datatalks-club
- MLA
- "A coding agent ran terraform destroy on a live environment it had misread as duplicates." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0004-claude-code-terraform-destroy-datatalks-club.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "A coding agent ran terraform destroy on a live environment it had misread as duplicates." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0004-claude-code-terraform-destroy-datatalks-club.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0004-claude-code-terraform-destroy-datatalks-club
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every destruction record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.