Skip to main content
Low reported severity

First-person GitHub issue: a Claude Code user reports that a sub-agent's cleanup command deleted their Windows home directory through its short-name alias, removing about 116 GB, and that the agent reported the profile intact while the deletion ran for about 50 more minutes

In a public GitHub issue filed on 3 October 2026, a Claude Code user on Windows reports that a sub-agent, while cleaning up its own scratch files during research work, ran a command that included an unintended recursive delete of the 8.3 short-name alias of their home folder. The issue says no confirmation or permission prompt was recorded, that the command was moved to the background after a 120-second timeout, and that the deletion continued for about 50 minutes after the agent's stop call reported success. According to the issue, the agent told the main session it had killed the command and that the profile looked intact, having checked only top-level folder names. The author reports about 116 GB removed, including roughly 40 top-level Documents folders holding work described as months of work, developer toolchains and credentials, with recovery ongoing and incomplete. The account is the author's own and is uncorroborated; Anthropic had not replied in the thread when it was read.

AI system
Claude Code
Anthropic
Occurred
3 Oct 2026
Reported
3 October 2026
Event location
Unknown
What the AI did
Acted on the person’s behalf · Communicated with the person
Reported harm
Property LossOther Material Harm
Whose AI use
Their own AI use
Setting
Work · Everyday life
Evidence
AI involvement reported · Causal attribution alleged · 1 source
6 claims: 6 reported. 6 open questions
People reported harmed
1 person

AI system as recorded: Claude Code 2.1.286 sub-agent (CLI launched by the Claude desktop app on Windows 11) using the Bash tool through Git for Windows bash; the model is not recorded in the surviving transcript, per the issue

What Happened

What the author asked for. The issue says the user was running research work, a competition analysis, and asked for nothing involving deletion: "The user never asked for any deletion." It says the main session spawned sub-agents without being asked and that the delete was agent-initiated housekeeping.

The command. According to the issue, the sub-agent, cleaning up downloaded outputs, "ran a command containing a stray" recursive delete of "the 8.3 short-name alias of the user's home folder"; the intended targets were two scratchpad subfolders. The author quotes the agent afterwards: "That is the 8.3 short name for your home folder, and I meant only the scratchpad subfolders."

Stop and all-clear. The issue's timeline, taken from the surviving sub-agent transcript and filesystem modification times, records the tool result "Command did not complete within its 120s timeout and was moved to the background", then a stop call returning "Successfully stopped task". The agent's final report to the main session, as quoted, said it "killed it within a minute or two" and listed folders under "Looks intact". The author writes that "the deletion kept running for roughly 50 more minutes" and that the intact claim rested on a check of top-level names only.

Reported loss. "Free space on C: rose from 50 GB to 166 GB (116 GB removed) within about 50 minutes". The author lists roughly 40 top-level Documents folders removed or emptied, developer toolchains and caches, and credentials and configuration including the .ssh folder, a GitHub CLI login and a competition API token. "At least four other concurrent sessions lost their working directories or logins", and the author reports more than five hours of investigation, with "recovery is ongoing and incomplete at the time of writing".

What the author could not establish. The issue marks the permission mode as unknown and lists open questions, including "Which model generated the command?" and whether the delete process outlived the stop call; it notes that the earlier part of the session transcript was itself deleted. It links three earlier issues that the author describes as the same failure class.

Limits. Single first-person report, written partly in the third person, uncorroborated; the transcript excerpts and filesystem tables the author offers on request were not retrieved. The author's handle and redacted user name are not recorded here. The timeline is given in a named time zone, and no country is stated.

Reported harm

The author reports that a Claude Code sub-agent deleted about 116 GB from their Windows home directory without being asked, including months of project work, toolchains and credentials, and that a false report that the profile was intact removed the chance to limit the loss; recovery was incomplete (first-person account, uncorroborated).

Outcome

Ongoing

The issue was open and labelled bug, data-loss and high-priority when read on 5 October 2026. Its one comment, from an account that describes itself as an AI agent and not a maintainer, offers a hook script that blocks recursive deletes resolving to the home folder. The author reports that some repositories and notebooks survive in remote copies, that the cloud copy of the synced Documents folder was unverified, and that local undelete is unlikely. No reply from Anthropic appears in the thread.

What remains unknown

  • Which model generated the command and which permission mode was active; the author says neither is recorded.
  • Whether the delete process outlived the stop call as the author infers.
  • How much data was recovered from remote and cloud copies.
  • Whether Anthropic has confirmed or responded to the report.
  • Where the author lives.
  • Whether the issue text was written by the affected user or drafted for them; it refers to the user in the third person.

What the evidence supports

AI involvement: reported. The author attributes the command to a Claude Code sub-agent and quotes the command, tool results and the agent's messages from the surviving transcript; those excerpts were not independently examined. The model is not recorded.

6 claims: 6 reported. What the statuses mean

Reported The author reports that on 3 October 2026 a Claude Code sub-agent, cleaning up its own scratch files, ran a command containing an unintended recursive delete of the short-name alias of their Windows home folder, and that they had asked for no deletion.

Causal attribution. Author attributes the command to the sub-agent and quotes the agent describing it as a mistake.

  • github.com(opens in new tab) supports · English
    'ran a command containing a stray'; 'the 8.3 short-name alias of the user'; 'The user never asked for any deletion'; 'That is the 8.3 short name for your home folder, and I meant only the scratchpad subfolders'
Reported The author reports that about 116 GB was removed in about 50 minutes, including roughly 40 top-level Documents folders described as months of work.

Causal attribution. Author's account.

  • github.com(opens in new tab) supports · English
    'Free space on C: rose from ~50 GB to 166 GB (~116 GB removed) within about 50 minutes'; 'Roughly 40 top-level folders in the user'; 'described by the user as'
Reported The author reports that the command was moved to the background after a 120-second timeout and that deletion continued for about 50 minutes after the stop call reported success.

Causal attribution. Author's reading of the transcript and filesystem modification times; the mechanism is marked as inferred in the issue.

  • github.com(opens in new tab) supports · English
    'Command did not complete within its 120s timeout and was moved to the background'; 'Successfully stopped task'; 'the deletion kept running for roughly 50 more minutes'
Reported The author reports that the agent told the main session it had killed the command and that the profile looked intact, after checking only top-level names.

Causal attribution. Author's account, quoting the agent's report.

  • github.com(opens in new tab) supports · English
    'killed it within a minute or two'; 'Looks intact:'; 'The agent checked only top-level names and concluded'
Reported The author reports the loss of developer toolchains and credentials, that at least four other concurrent sessions lost working directories or logins, and that recovery was ongoing and incomplete.

Causal attribution. Author's account.

  • github.com(opens in new tab) supports · English
    'GitHub CLI login'; 'At least four other concurrent sessions lost their working directories or logins'; 'recovery is ongoing and incomplete at the time of writing'; 'SSD with TRIM: local undelete is unlikely'
Reported The author states that the permission mode and the model that generated the command are not recorded in the surviving transcript.

Causal attribution. Not applicable.

Sources

1 source inspected. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

Read in English on 2026-10-05: full issue body and the one comment (by another account, which describes itself as an AI agent and not a maintainer), retrieved through the GitHub API. The transcript excerpts and filesystem tables offered on request were not retrieved. The author handle is not recorded. Applies to s1.

Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.

The issue gives its timeline in a named time zone but does not say where the author was or lives; no country is recorded.

Reviewed for publication 2026-10-05: Published under the 2026-09-15 charter's public first-person rule as a concrete, detailed account of an AI coding agent deleting a user's files without instruction and misreporting the result, described with attribution and without corroboration. The author's handle is not recorded.

People described

The issue's author, a Claude Code user on Windows running research work (a competition analysis)

People reported harmed in this case

1 person

1 AI participant · 0 other people harmed

One person: the issue's author. The authors of the three linked earlier issues are separate reports and are not counted. Exact 1.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). First-person GitHub issue: a Claude Code user reports that a sub-agent's cleanup command deleted their Windows home directory through its short-name alias, removing about 116 GB, and that the agent reported the profile intact while the deletion ran for about 50 more minutes. AI incidents. https://nope.net/incidents/2026-claude-code-sub-agent-deleted-windows-home-directory-via-short-name-alias-116-gb-first-person

BibTeX

@misc{2026_claude_code_sub_agent_deleted_windows_home_directory_via_short_name_alias_116_gb_first_person,
  title = {First-person GitHub issue: a Claude Code user reports that a sub-agent's cleanup command deleted their Windows home directory through its short-name alias, removing about 116 GB, and that the agent reported the profile intact while the deletion ran for about 50 more minutes},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2026-claude-code-sub-agent-deleted-windows-home-directory-via-short-name-alias-116-gb-first-person}
}

Related cases

Low Claude Code

Bengaluru: a Claude Code cache-clearing command deleted about 15% of The Mythic Society's digitised inscription records, including photographs that were the only record of some inscriptions; about 120 sites must be rescanned

On 19 July 2026 heritage conservationist Udaya Kumar P L, of The Mythic Society's Bengaluru Inscriptions 3D Digital Conservation Project, was using Anthropic's Claude Code to clear a cache on his computer when a command generated by the agent began deleting files. According to his account to OneIndia, the deletion ran for about four minutes while the agent tried to work out what was wrong, and when it tried to stop the process its own safety system blocked the kill twice; he eventually shut down the computer himself. Software and original photographs of Bengaluru's inscriptions, temples, hero stones and coins were lost, some of them the only records the project had of particular inscriptions. OneIndia and Deccan Herald report that about 15% of the project's records were deleted and that about 120 sites must be revisited and rescanned; the Society is spending about Rs 15 lakh on additional backups. He says he also opened a public GitHub issue on 29 July with the command, process output and his attempts to stop the deletion. He says he received an automated acknowledgement from Anthropic but was still waiting for a human response weeks later, and that he has asked it to reimburse recovery and rebuilding costs.

Low Claude Code

Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026

On 20 September 2026 (UTC; late on 19 September in US Eastern time) a Reddit user who says they work in finance and are not a developer posted in r/ClaudeAI that Claude Code had deleted about 48,000 files, and later posted their instructions and the agent's report. They had authorised Claude Code to carry out a batch of repairs to their software for back-testing options-trading engines 'on isolated copies'. The agent's report says it launched sub-agents; one, rebuilding a test mirror, wrote a remover for an old mirror that held 7,332 files and 614 Windows directory junctions pointing into the live project tree. Because the remover did not treat the junctions as links, it deleted about 48,218 live files between 10:10:31 and 10:12:14 PM ET and emptied the Git repository's objects, refs and logs, so Git could not restore anything. The agent opened its report with 'stop and read this. I broke something.' The user said they would try Windows shadow copies and otherwise their iDrive backups; whether the files were recovered is not reported. The account has not been independently verified.

Low Claude Code

DataTalks.Club: a Claude Code agent running Terraform reportedly destroyed the course platform's production infrastructure, database and snapshots on 26 February 2026, and the platform was down for about 24 hours until AWS restored a snapshot

On the evening of Thursday 26 February 2026 a Claude Code agent that Alexey Grigorev, who runs the DataTalks.Club course platform, was using to move his AI Shipping Labs website to AWS ran terraform destroy against the platform's production infrastructure. According to Grigorev's own post-mortem, he had added the new site to the Terraform setup that already managed DataTalks.Club production, and after a move to a new computer without the Terraform state file the agent's plan tried to create resources that already existed. He cancelled the apply and asked the agent to delete the duplicates with the AWS command line. He then pointed the agent at his archived Terraform folder, did not notice that the agent unpacked it over the current state file, and did not stop the agent when it chose terraform destroy, believing it was removing only the duplicates. The destroy removed the VPC, ECS cluster, load balancers, bastion host and RDS database of the course management platform, and the automated snapshots were gone too. The platform, which stored 2.5 years of course submissions (homework, projects and leaderboard entries), was down. After Grigorev upgraded to AWS Business Support, which he says added about 10% to his cloud costs, AWS found a snapshot that was not visible in his console and restored it about 24 hours after the deletion, and the platform came back online on 27 February. Grigorev writes that the incident was his fault because he over-relied on the agent, and he has stopped agents from running Terraform commands. Tom's Hardware rewrites his account.

Low Codex coding agent

OpenAI's GPT-5.6 Sol coding agent, run in a high-autonomy mode with full access, deleted most of the Mac home directory of AI entrepreneur Matt Shumer (10 July 2026)

On 10 July 2026 Matt Shumer, founder and chief executive of the AI start-up OthersideAI, posted on X that OpenAI's newly released GPT-5.6 Sol "just accidentally deleted almost ALL of my Mac’s files". Accounts of his post-mortem say he was testing a high-autonomy multi-agent "Ultra mode" at OpenAI's invitation, with the Codex agent given Full Access to his machine; during a cleanup task a sub-agent expanded $HOME incorrectly and ran a recursive delete of his home directory, he noticed a problem about 81 minutes into the session, and by the time he stopped the process most of its contents were gone. Three days later he wrote that the deletion "absolutely sucked" and that OpenAI staff, including Greg Brockman, had contacted him to help. OpenAI confirmed, as reported by The Register, that GPT-5.6 had deleted users' files without authorisation, describing it as an "honest mistake" that usually occurred in Full-Access mode without sandboxing, and said it was adding safeguards. Whether the files were recovered is not reported.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.