A Claude Code Agent Deleted 48,218 Files in 103 Seconds. Here Is the Technical Chain.
A Claude Code Agent Deleted 48,218 Files in 103 Seconds. Here Is the Technical Chain.
Section titled “A Claude Code Agent Deleted 48,218 Files in 103 Seconds. Here Is the Technical Chain.”A developer gave Claude Code a routine cleanup job. In 103 seconds the agent deleted 48,218 live files and emptied the project’s Git object store (TechRadar). The work was not recoverable through normal Git history (Cyber Security News). The incident surfaced on Reddit on September 20 and spread through the developer community by September 27 (Progressive Robot).
The story matters because the failure was not a wild model hallucination. It was a filesystem abstraction that the agent’s cleanup script misread. Any team running agentic coding tools can hit the same wall.
What the agent was asked to do
Section titled “What the agent was asked to do”The developer used Claude Code to repair a collection of software that analyzes historical stock-options data (TechRadar). The instructions were explicit: make copies of relevant files, work on the copies, test the repairs, and leave the original working files alone (TechRadar).
The task ran as 11 repair jobs. Ten went smoothly. The last one rebuilt a testing environment called a “mirror”, a copy of a file set used for testing (TechRadar).
The junction blind spot
Section titled “The junction blind spot”The mirror contained 7,332 ordinary files and 614 Windows directory junctions that pointed back into the live project tree (Progressive Robot). A junction looks like an ordinary folder but points to a separate location. In this case the junctions pointed at the user’s live working files (TechRadar).
The agent wrote a cleanup script to clear the old mirror. The script used os.walk(..., followlinks=False) as a safeguard (Cyber Security News). The assumption was that this would prevent traversal into linked directories (Cyber Security News).
On Windows, that assumption failed. os.path.islink() returned false for the junctions, so the script did not treat the directories beneath them as linked paths (Cyber Security News). The script protected files directly at a junction’s root, but nested directories below those folders were walked and deleted (TechRadar).
The agent followed the junctions into the real working files and deleted them (TechRadar).
The numbers
Section titled “The numbers”The cleanup removed 55,550 files. Of those, about 7,332 were the mirror files meant for deletion. The remaining 48,218 files were from the live working environment (TechRadar).
The deletion ran from 10:10:31 p.m. to 10:12:14 p.m. Eastern time, a window of 103 seconds (Progressive Robot). That is roughly 468 files per second (Progressive Robot).
The agent’s own log counted 55,550 files, 614 junctions, and 1,808 directories (Cyber Security News). The verifier counted 728 emptied directories, including 418 beneath the “Runners” directory. Root files, documentation, backups, and chat transcripts outside the affected tree stayed intact (Cyber Security News).
Why Git did not save it
Section titled “Why Git did not save it”The damage extended to the project’s .git/objects, refs, and logs directories. They were left empty, so git log could not find commits (Cyber Security News). The index survived and continued to list 7,221 paths, but the underlying blobs were gone, which blocked Git-based recovery (Cyber Security News).
The developer admitted in the archived post that they were not properly using GitHub or another remote for immediate corrections, even though the work should have been on a branch (TechRadar). Had the commits been pushed to a remote, the work could have been restored (TechRadar).
What Claude Code itself said
Section titled “What Claude Code itself said”The agent was honest about the failure. At one point it told the developer: “Craig, stop and read this. I broke something.” (TechRadar).
Honesty did not undo the deletion. Claude Code’s checkpoint feature would not rescue this scenario because changes made through Bash commands, including deletions, are not tracked for rewind (Cyber Security News).
The incident has not been independently verified as a specific Claude Code defect. The numbers come from the user’s report and the agent’s own logs (Cyber Security News).
The guardrails that stop this
Section titled “The guardrails that stop this”Anthropic’s documentation lists the controls that matter here. Manual mode requests approval for Bash commands and file modifications. bypassPermissions skips those prompts and should be used only inside isolated containers or virtual machines (Cyber Security News). The incident shows why permission control and filesystem boundaries exist (Anthropic security docs).
The practical rules for any team running agentic coding tools:
- Never let an agent work on the only copy of something you cannot lose. Git, backups, and sandboxes all help, but a copy the agent cannot reach is what turns a deletion into a non-event (Progressive Robot).
- Push to a remote constantly. GitHub is a “save button”. Not having a remote backup for a project with tens of thousands of files is how a data loss becomes permanent (TechRadar).
- Audit the filesystem abstractions in any folder an agent may clean. Watch for directory junctions and symbolic links, especially on Windows (Progressive Robot).
- Run native-Windows agents inside WSL2 or a container. The built-in sandbox does not run on native Windows (Progressive Robot).
- Treat deletion as a permission, not a convenience. A tool that can complete a maintenance task can also execute an unsafe implementation of it (Cyber Security News).
The lesson is not that agents are unsafe. The lesson is that an agent inherits the permissions you grant it, and it executes at machine speed. Treat agentic tools like privileged automation, not like a chat window (Yahoo Tech). The boundaries you set before the run are the only ones that will hold during it.