Logo
FrontierNews.ai

Claude Code Deleted 48,000 Files in 103 Seconds. Here's What Went Wrong

A Claude Code agent reportedly deleted nearly 48,000 files from a developer's project in less than two minutes by following hidden Windows shortcuts into the wrong folders, then told the developer it had broken something. The incident, posted to Reddit on September 20, 2026, and later deleted, has reignited concerns about how AI coding tools handle destructive operations on personal computers.

What Exactly Happened with Claude Code?

According to the developer's account, he asked Claude Code to run repair jobs on copies of his project, which contained historical stock options data used for testing trading ideas. One of the helper agents wrote a Python cleanup script to clear out an old folder copy before rebuilding it. The script ran for exactly 103 seconds, from 10:10:31 pm to 10:12:14 pm Eastern time, and deleted approximately 55,550 files total.

The problem: only about 7,332 of those files were the old copy the script was supposed to delete. The other 48,218 were live project files that should have been protected. The script also wiped the project's Git history, making it impossible to restore anything through version control.

Why Did Claude Code Delete the Wrong Files?

The root cause involves a Windows feature called junctions, which are shortcuts that make one folder appear inside another while the actual files live elsewhere. Think of it like a door in a wall that opens into a completely different room. The cleanup script was configured not to follow links, but on Windows, the check it used does not recognize junctions as links. So the script walked through those doors into the real project and deleted everything it found.

The script even had a safety guard, but it only protected files at the very top of each junction, not the folders underneath. A final verification check also passed by mistake because it confirmed the junction folders still existed, which they did, but failed to notice that their contents were gone.

How Common Are These AI Agent Incidents?

This is not an isolated case. In July 2025, an AI coding tool from Replit reportedly deleted a company's database during a code freeze. Google's Gemini CLI also reportedly lost a user's files after a failed folder move. The pattern repeats: an AI tool with permission to change things, real data with no separate copy, and a mistake that looks routine until it is over.

The incident comes as Nvidia launched its Open Agent Safety Platform on September 28, 2026, specifically designed to prevent AI agents from accessing unauthorized files, networks, or systems if they attempt to bypass their sandbox restrictions. Nvidia's vice president noted that if the platform had been used for early model evaluations, it could have prevented the Hugging Face incident in July 2026, where OpenAI agents were involved.

What Should You Do If an AI Agent Deletes Your Files?

  • Stop immediately: Stop the agent and stop using that drive. New files can overwrite the space where your deleted files still sit, making recovery impossible.
  • Check backups first: Look at cloud backup, an external drive, a network drive, or OneDrive folders. The developer in this case had backups on a network drive and a cloud service.
  • Try Windows previous versions: Right-click the folder, choose Properties, and open the Previous Versions tab. This only helps if restore points or File History were turned on before the deletion.
  • Check your Git remote: If you pushed to GitHub or a similar service, download a fresh copy. A local Git folder that was deleted cannot bring anything back.
  • Use recovery software as a last resort: Results vary. On many modern SSDs, deleted files are cleared quickly and cannot be recovered at all.

Remember that files removed by a script do not go to the Recycle Bin. They are usually gone straight away.

How to Protect Your Work from AI Agent Mistakes

  • Push code to a remote: Use GitHub, GitLab, or a similar service. A Git folder on the same computer is not a backup.
  • Back up data separately: Datasets and large files need their own backup. Keep one copy the AI tool cannot reach, and test that you can restore it.
  • Let the agent work on a copy: Use a separate folder, a virtual machine, or a container, and keep your originals out of its reach.
  • Do not turn off approval prompts: Skipping them is only sensible in a throwaway, isolated environment. In manual mode, Claude Code asks before running commands and changing files, though approving a command like "run this script" does not show you every file the script will delete.
  • Ask for a dry run: Before any deletion, ask the agent to list what it will delete, and check the number matches what you expect.
  • Prefer moving over deleting: Ask it to move files to a holding folder instead of removing them.
  • Be careful with shortcuts and links: If a folder contains junctions or symbolic links, treat any cleanup inside it as risky.
  • Keep one human check: Do not say "just proceed" for destructive steps. Keep one human check before anything that cannot be undone.

Is This Story Verified?

The details come from a Reddit post, a photo of the screen, and a report written by the agent itself. The author later deleted the account, and no independent investigation has been published. Anthropic has not issued a statement about the incident. However, the story is believable: the file counts add up, the timing works out to exactly 103 seconds, and the way junctions confuse cleanup scripts is a well-known problem in Windows development.

The incident highlights a broader challenge as AI agents become more autonomous. Nvidia's new safety platform includes OpenShell, an open-source runtime that applies policies to agent actions, and Sentry, which monitors agent activity at the network level to detect suspicious behavior. The documentation for OpenShell lists support for agents such as Claude Code, OpenCode, and the GitHub Copilot CLI.

The lesson is not that safety features are useless. It is that a script the agent writes for itself can hide danger that a simple command check cannot see. As more developers rely on AI coding tools, the responsibility to isolate, backup, and verify becomes more critical than ever.