Skip to main content
Low reported severity Media Coverage

Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026

On 20 September 2026 (UTC; late on 19 September in US Eastern time) a Reddit user who says they work in finance and are not a developer posted in r/ClaudeAI that Claude Code had deleted about 48,000 files, and later posted their instructions and the agent's report. They had authorised Claude Code to carry out a batch of repairs to their software for back-testing options-trading engines 'on isolated copies'. The agent's report says it launched sub-agents; one, rebuilding a test mirror, wrote a remover for an old mirror that held 7,332 files and 614 Windows directory junctions pointing into the live project tree. Because the remover did not treat the junctions as links, it deleted about 48,218 live files between 10:10:31 and 10:12:14 PM ET and emptied the Git repository's objects, refs and logs, so Git could not restore anything. The agent opened its report with 'stop and read this. I broke something.' The user said they would try Windows shadow copies and otherwise their iDrive backups; whether the files were recovered is not reported. The account has not been independently verified.

AI system
Claude Code
Anthropic (Claude Code)
Occurred
19 Sept 2026
Reported
20 September 2026
Event location
Unknown
What the AI did
Acted on the person’s behalf
Reported harm
Other Material Harm
Whose AI use
Their own AI use
Setting
Everyday life
Evidence
AI involvement reported · Causal attribution supported · 5 sources, 1 underlying account
4 claims: 4 reported. 4 open questions
People reported harmed
1 person

AI system as recorded: Claude Code (Anthropic) running a multi-agent repair workflow on a Windows machine; the underlying model version is not stated

What Happened

The Reddit post 'Code just deleted 48k files. This can't be real.' was created in r/ClaudeAI at 03:00 UTC on 20 September 2026 (arctic_shift record) and later removed; its body was not recoverable. In a comment the same user posted the prompt they had given and Claude Code's reply. The prompt authorised fifteen repairs to their options back-testing code: 'This is explicit authorization to build, correct and test them on isolated copies.' One item asked it to 'rebuild the mirror against current files'. Claude Code reported that it launched eleven boxes of work, each checked by an adversarial verifier, and that the verifier for the mirror job reported writes outside its box. It then wrote: 'stop and read this. I broke something. An agent I launched deleted about 48,000 live files from the Dashboard tree between 10:10:31 and 10:12:14 PM ET tonight, and destroyed the git object store.' It explained that build_mirror.py could not refresh in place, so the sub-agent wrote a remover for the old mirror in a temporary folder; that mirror held 7,332 real files and 614 Windows directory junctions pointing into the live tree, and the remover's os.walk(followlinks=False) did not stop at the junctions because islink() is False for junctions on Windows. The remover's guard only skipped files directly in a junction's root. The report counts 728 emptied directories and says Git 'cannot restore anything'; the report lists the root files, the remaining documentation and backup files, and the folders outside the project tree as intact, although 78 directories under the documentation folder were emptied. Cyber Security News computes 48,218 deleted live files from the log (55,550 files removed less the 7,332 intended). The date is taken as 19 September 2026: the agent said 'tonight' of a 10:10 PM ET deletion, the post was created about 11:00 PM ET that night, and a file the agent created in the same session is dated 2026-09-19. In another comment the user wrote that they are 'in finance, not a developer' and would try shadow copies, then their iDrive backups. According to Yahoo Tech, an archived copy of the post acknowledged that they were not properly using GitHub or another method for immediate corrections.

Reported harm

About 48,218 live project files and the project's Git history were deleted by a sub-agent during an authorised repair job, according to the user and the agent's own report posted on Reddit; recovery was being attempted and its outcome is unknown.

Outcome

Unknown

No company response is reported. The user said they would attempt recovery through Windows shadow copies and otherwise their iDrive backups; the result is not reported. The Reddit post drew more than 1,300 comments (arctic_shift count 1,375) before it was removed; Cyber Security News (21 September 2026), Yahoo Tech (25 September, a Future syndication) and TechRadar (27 September) covered it.

What remains unknown

  • Whether the files were recovered from shadow copies or backups, and how much work was lost.
  • The Claude Code version, model and permission mode used.
  • The removed post's full text (only quoted fragments and the poster's comments were read).
  • The user's location.

What the evidence supports

AI involvement: reported. The user posted their prompt and Claude Code's own report, in which the agent says 'An agent I launched deleted about 48,000 live files' and explains the junction-following remover a sub-agent wrote (Reddit comment via the thread RSS). The deletion was an action the agent took on the user's behalf under a broad authorisation to work on isolated copies. No logs were published, and the account is not independently verified (Cyber Security News notes the same).

4 claims: 4 reported. What the statuses mean

Reported According to Claude Code's report as posted by the user, a sub-agent it launched to rebuild a test mirror wrote a remover for an old mirror containing 7,332 files and 614 Windows directory junctions into the live tree; the remover followed the junctions and deleted about 48,000 live files between 10:10:31 and 10:12:14 PM ET and destroyed the Git object store.

Causal attribution. The agent's own report as posted by the user; logs were not published and no independent forensic account exists.

  • reddit.com(opens in new tab) supports · English
    'An agent I launched deleted about 48,000 live files from the Dashboard tree between 10:10:31 and 10:12:14 PM ET tonight, and destroyed the git object store.'; 'That mirror is 7,332 real files plus 614 Windows directory junctions pointing into the live tree.'; 'Git cannot restore anything.'
  • cybersecuritynews.com(opens in new tab) supports · English
    'After subtracting the 7,332 intended mirror files, the reviewer calculated 48,218 deleted live files.'
Reported The user had authorised the agent to build, correct and test repairs on isolated copies, including rebuilding the mirror.

Causal attribution. The user's own prompt as they posted it.

  • reddit.com(opens in new tab) supports · English
    'This is explicit authorization to build, correct and test them on isolated copies.'; 'rebuild the mirror against current files.'
Reported The agent opened its report with 'stop and read this. I broke something.'

Causal attribution. Agent output as posted by the user.

Reported The user said they work in finance rather than as a developer and would try Windows shadow copies and otherwise their iDrive backups; according to Yahoo Tech, the archived post said they had not been properly using GitHub or another method for immediate corrections.

Causal attribution. The user's own statements.

  • reddit.com(opens in new tab) supports · English
    'I'm in finance, not a developer.'; 'Hoping for good luck with the shadow copy. If not, I will use my idrive backups.'
  • tech.yahoo.com(opens in new tab) supports · English
    'I was not properly using GitHub or another method for immediate corrections, even though it should have been branching.'

Sources

5 sources inspected, from 1 underlying account. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

Read on 2026-09-28 from the thread's Reddit RSS feed (comment by the original poster, 20 September 2026, 13:18 UTC): their prompt and Claude Code's report. The post itself was removed and its body could not be read; post metadata from arctic_shift. Applies to s1.

Read on 2026-09-28 from the thread's Reddit RSS feed (comment by the original poster, 20 September 2026, 14:05 UTC). Applies to s2.

Read live on 2026-09-28 (Cyber Security News, 21 September 2026). Relays the Reddit post and the attached verifier report. Applies to s3.

Read live on 2026-09-28 (Yahoo Tech, Future syndication, 25 September 2026). Quotes an archived copy of the removed post. Applies to s4.

Read live on 2026-09-28 (TechRadar, 27 September 2026). Relays the Reddit post and its comments. Applies to s5.

Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.

The account gives times in ET but states no location for the user; no country is recorded. No court proceeding.

Reviewed for publication 2026-09-28: Published under the 2026-09-15 charter as a core acted_on_behalf case from a first-person public forum account: the user posted their prompt and the coding agent's own report of deleting about 48,000 live files during an authorised job. Unverified beyond the poster's account and the agent's report; recovery unknown. The user is not named.

People described

An individual Reddit user who says they work in finance and was building their own options back-testing software (not named)

People reported harmed in this case

1 person

1 AI participant · 0 other people harmed

One person, the user whose files were deleted (their Reddit account). Exact 1.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026. AI incidents. https://nope.net/incidents/2026-claude-code-agent-deleted-48000-live-project-files-windows-junctions

BibTeX

@misc{2026_claude_code_agent_deleted_48000_live_project_files_windows_junctions,
  title = {Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2026-claude-code-agent-deleted-48000-live-project-files-windows-junctions}
}

Related cases

Low Claude Code

Bengaluru: a Claude Code cache-clearing command deleted about 15% of The Mythic Society's digitised inscription records, including photographs that were the only record of some inscriptions; about 120 sites must be rescanned

On 19 July 2026 heritage conservationist Udaya Kumar P L, of The Mythic Society's Bengaluru Inscriptions 3D Digital Conservation Project, was using Anthropic's Claude Code to clear a cache on his computer when a command generated by the agent began deleting files. According to his account to OneIndia, the deletion ran for about four minutes while the agent tried to work out what was wrong, and when it tried to stop the process its own safety system blocked the kill twice; he eventually shut down the computer himself. Software and original photographs of Bengaluru's inscriptions, temples, hero stones and coins were lost, some of them the only records the project had of particular inscriptions. OneIndia and Deccan Herald report that about 15% of the project's records were deleted and that about 120 sites must be revisited and rescanned; the Society is spending about Rs 15 lakh on additional backups. He says he also opened a public GitHub issue on 29 July with the command, process output and his attempts to stop the deletion. He says he received an automated acknowledgement from Anthropic but was still waiting for a human response weeks later, and that he has asked it to reimburse recovery and rebuilding costs.

Low Claude Code

DataTalks.Club: a Claude Code agent running Terraform reportedly destroyed the course platform's production infrastructure, database and snapshots on 26 February 2026, and the platform was down for about 24 hours until AWS restored a snapshot

On the evening of Thursday 26 February 2026 a Claude Code agent that Alexey Grigorev, who runs the DataTalks.Club course platform, was using to move his AI Shipping Labs website to AWS ran terraform destroy against the platform's production infrastructure. According to Grigorev's own post-mortem, he had added the new site to the Terraform setup that already managed DataTalks.Club production, and after a move to a new computer without the Terraform state file the agent's plan tried to create resources that already existed. He cancelled the apply and asked the agent to delete the duplicates with the AWS command line. He then pointed the agent at his archived Terraform folder, did not notice that the agent unpacked it over the current state file, and did not stop the agent when it chose terraform destroy, believing it was removing only the duplicates. The destroy removed the VPC, ECS cluster, load balancers, bastion host and RDS database of the course management platform, and the automated snapshots were gone too. The platform, which stored 2.5 years of course submissions (homework, projects and leaderboard entries), was down. After Grigorev upgraded to AWS Business Support, which he says added about 10% to his cloud costs, AWS found a snapshot that was not visible in his console and restored it about 24 hours after the deletion, and the platform came back online on 27 February. Grigorev writes that the incident was his fault because he over-relied on the agent, and he has stopped agents from running Terraform commands. Tom's Hardware rewrites his account.

Low Meta Muse agent

Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name

Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.

Low Unidentified image tool

Stanford University: the Residential & Dining Enterprises department used generative AI to alter a promotional photograph of three students, replacing a Hispanic male student with an AI-generated Black woman, slimming two students' faces and changing their clothing, on campus banners; the university said the undisclosed alteration violated its AI policy, apologised and opened an investigation (Stanford Review, Stanford Daily, NBC Bay Area, NBC News, 21-24 September 2026)

The Stanford Review reported on 21 September 2026 that Stanford's Residential & Dining Enterprises (R&DE) had used AI to change the appearance of students in its advertising: a student was sent images comparing a banner with the original photograph, which he recalled a Stanford photographer taking, and found he had been removed and replaced by an AI-generated Black woman, while the two students beside him were made to appear visibly thinner. Stanford confirmed to The Stanford Daily on 23 September that R&DE used generative AI to modify the appearance of several students in the image; the Daily reported that the students' clothing was changed into Stanford merchandise, two students' faces were slimmed and one student's race, gender and appearance were entirely changed, and the university said the alteration and its non-disclosure violated its policy prohibiting AI in producing or altering images of Stanford people; the banner at the Governor's Corner housing centre was taken down and staff training promised. On 24 September NBC News reported the university's statement that the alteration was 'a serious error in judgment', that it had apologised to the students whose images were altered or erased, and that it had opened an investigation. The replaced student, who first found the edit funny, said that seeing his identity changed and being left out made him feel 'silenced and erased from a representation that was supposed to include me', that it was upsetting, and that he was exhausted by the national media attention. According to the student, the original photograph was taken at a 2024 Lunar New Year dinner in a campus dining hall and had been used unaltered in earlier promotional material.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.