Claude Code Deleted 48,000 Files in 103 Seconds: What Happened and How to Protect Your Own

A developer says an AI coding agent wiped out more than 48,000 of his files in under two minutes, and then told him it had broken something. The story went viral this week, and it raises a simple question for anyone who lets AI tools work on their computer: what if this happened to me?

This guide explains what reportedly happened, why it happened, what you can do if an AI tool deletes your files, and how to make sure it cannot ruin your work.

Quick Answer

  • A Reddit user reported that a Claude Code agent deleted 48,218 live files from his Windows project in 103 seconds
  • It happened on the night of September 19, 2026, and was posted on September 20
  • The agent wrote a small clean-up script that followed hidden shortcut folders (called junctions) back into the real project and deleted what was inside
  • The project’s Git history was wiped too, so Git could not restore anything
  • This is a user-reported incident. It has not been independently verified, and the original post was later deleted
  • The developer said he had backups on a network drive and a cloud service
  • If it happens to you: stop, do not save anything new to that drive, and check your backups first

What Reportedly Happened

According to the developer’s post, he asked Claude Code to run a set of repair jobs on copies of his project. It was a personal computer, and the project held historical stock options data used for testing trading ideas.

One of the helper agents needed to clear out an old copy of a folder before rebuilding it. It wrote its own small Python script to do that. The script ran from 10:10:31 pm to 10:12:14 pm Eastern time, which is 103 seconds. In that time it removed about 55,550 files. Only around 7,332 of them were the old copy it was supposed to delete. The other 48,218 were real files from the live project.

When the work finished, another checking agent flagged that something had gone outside its box. Claude then checked the damage itself and started its report to the developer with the words “I broke something.”

Why Did It Happen

The old copy of the folder was full of junctions. A junction is a Windows shortcut that makes one folder appear inside another, but the files really live somewhere else. Think of it like a door in a wall that opens into a completely different room.

The clean-up script was set up not to follow links. But on Windows, the check it used does not recognize junctions as links. So the script walked through those doors, into the real project, and deleted everything it found. It even had a safety guard, but the guard only protected files at the very top of each junction, not the folders underneath.

A final check after the deletion also passed by mistake. It confirmed the junction folders still existed, which they did, but did not notice that their contents were gone.

What Was Lost and What Survived

Lost:

  • 48,218 files from the live project folder
  • The project’s Git history. The folders that store it were emptied, so Git could no longer restore anything
  • About 728 folders were left empty

Survived:

  • The main code files at the top of the project
  • A separate Backups folder and other folders that were not behind a junction
  • The copies the agents were working on

The developer said he had a copy on a network storage drive and an overnight cloud backup, and that his first step was checking a Windows shadow copy. His post did not say how much came back.

Is This Story Confirmed

Not fully, and it is worth being clear about that. The details come from a Reddit post, a photo of the screen, and a report written by the agent itself. The author later deleted the account, and no independent investigation has been published. Cyber Security News described it as an alleged incident, and none of the coverage we reviewed included a statement from Anthropic.

The details do hang together, though. The file counts add up, the timing works out to exactly 103 seconds, and the way junctions confuse this kind of script is a well-known problem. So it is a believable story, but treat it as a warning, not a proven fact.

Whose Fault Was It

Most likely both sides share it.

The agent’s script had real mistakes. It used a shallow safety guard, a check that only tested that folders existed, and a hand-written delete loop when a standard tool would have handled junctions safely.

The setup left no safety margin. The agents were told to keep going without asking, they worked in the same folder as the only live copy, and the Git history sat inside the same project, so one mistake could reach it. The developer himself said he should have been using GitHub and branches.

Did Claude Code’s Safety Features Fail

The post does not say which permission mode the session used, so we cannot say for certain. What we do know from Anthropic’s published guidance, as summarized by Cyber Security News:

  • In the manual mode, Claude Code asks before running commands and changing files. Even then, approving a command like “run this script” does not show you every file the script will delete
  • The mode that skips all prompts is meant only for isolated containers or virtual machines
  • The rewind and checkpoint feature does not track deletions made through shell commands, so it would not have brought these files back

The lesson is not that safety features are useless. It is that a script the agent writes for itself can hide danger that a simple command check cannot see.

This Is Not the First Time

Similar stories have appeared before. In July 2025, an AI coding tool from Replit reportedly deleted a company’s database during a code freeze, and Google’s Gemini CLI reportedly lost a user’s files after a failed folder move. The pattern is the same each time: an AI tool with permission to change things, real data with no separate copy, and a mistake that looks routine until it is over.

The problem is not limited to one company. It applies to any AI tool that can run commands on your computer. If you are choosing between them, our list of AI coding tools is a good starting point.

If an AI Agent Deleted Your Files: What to Do Right Now

  1. Stop the agent and stop using that drive. New files can overwrite the space where your deleted files still sit.
  2. Check your backups first. Look at cloud backup, an external drive, a network drive, or OneDrive folders.
  3. Try Windows previous versions. Right-click the folder, choose Properties, and open the Previous Versions tab. It only helps if restore points or File History were turned on before the deletion.
  4. If you use Git, check your remote. If you pushed to GitHub or a similar service, download a fresh copy. A local Git folder that was deleted cannot bring anything back.
  5. Use recovery software only as a last resort. Results vary. On many modern SSDs, deleted files are cleared quickly and cannot be recovered at all.

Also remember that files removed by a script do not go to the Recycle Bin. They are usually gone straight away.

How to Protect Your Files From AI Agents

Most of these are old habits that matter even more now.

  • Push your code to a remote. GitHub, GitLab, or similar. A Git folder on the same computer is not a backup.
  • Back up your data separately. Datasets and large files need their own backup. Keep one copy the AI tool cannot reach, and test that you can restore it.
  • Let the agent work on a copy. Use a separate folder, a virtual machine, or a container, and keep your originals out of its reach.
  • Do not turn off the approval prompts. Skipping them is only sensible in a throwaway, isolated environment.
  • Ask for a dry run. Before any deletion, ask the agent to list what it will delete, and check the number matches what you expect.
  • Prefer moving over deleting. Ask it to move files to a holding folder instead of removing them.
  • Be careful with shortcuts and links. If a folder contains junctions or symbolic links, treat any clean-up inside it as risky.
  • Do not say “just proceed” for destructive steps. Keep one human check before anything that cannot be undone.

Is Claude Code Safe to Use

Used with normal care, yes. Millions of people run coding agents without losing files. The risk grows when you approve scripts without reading them, skip approval prompts, or let agents work on your only copy of important data. If your team uses Claude Code heavily, it is also worth thinking about cost and access controls, as we covered in our piece on the JPMorgan Claude spending cap.

This also fits a bigger pattern this year of AI agents doing things nobody asked for, like the OpenAI agent that entered an Australian government portal or the Gemini test that reached real companies. The common answer is the same: limit what an agent can touch, and keep a copy it cannot reach.

Frequently Asked Questions

Did Claude Code really delete 48,000 files?

According to a developer’s Reddit post and a report written by the agent, a script created by a Claude Code helper deleted 48,218 live files. This has not been independently verified, and the original post was later deleted.

How did it delete so many files so fast?

Deleting files is very quick for a computer. The script removed about 55,550 files in 103 seconds, roughly 540 per second, so no person could have stopped it in time.

What is a junction?

A junction is a Windows shortcut that makes a folder appear in a second location while the files stay in the original place. Deleting through a junction can delete the real files.

Can I get files back that an AI tool deleted?

Possibly. Check cloud and external backups first, then the Previous Versions tab on the folder, then a fresh copy from GitHub if you pushed your code. Recovery software is a last resort and often fails on SSDs.

Would the Recycle Bin have saved them?

Usually not. Files deleted by a script or command normally skip the Recycle Bin.

Did Claude Code’s rewind feature help?

No. Anthropic’s guidance says checkpoints do not track deletions made through shell commands.

How do I stop an AI agent from deleting my files?

Work on a copy, keep backups and a remote Git copy, leave approval prompts on, and ask for a list of what will be deleted before anything is removed.

Is this only a Claude Code problem?

No. Any AI tool that can run commands on your computer can make this kind of mistake. Similar incidents have been reported with other coding tools.

Leave a Reply

Your email address will not be published. Required fields are marked *