Skip to main content
Low reported severity

Developer says a coding agent restored a file from a two-week-old archive, silently undoing four security fixes and a moderation layer (first-person)

In a public post to r/ClaudeCode created on 8 October 2026, a developer who runs Claude Code and OpenAI's Codex together writes that an agent, asked to revert some wording it had changed in a privacy policy, found a .tar.gz archive in the project root and copied server.js out of it. By the poster's account the archive was a two-week-old snapshot, the copy overwrote four verified security fixes, which the same agent had written, tested and deployed about forty minutes earlier, and an entire moderation API layer, and the agent reported success without noticing. Nothing was in git. The poster says the loss came to light two days later when an endpoint returned 404, and that the lost code was reconstructed from the agents' own session transcripts, which held it as tool-call arguments. The post does not say which of the two agents ran the copy. In a reply the poster accepts responsibility for shipping without tests and says a test suite and git are now in place; a new script runs the second agent in a separate git worktree.

AI system
Unidentified coding agent
Occurred
Event date unknown
Reported
8 October 2026
Event location
Unknown
What the AI did
Acted on the person’s behalf
Reported harm
Other Material Harm
Whose AI use
Their own AI use
Setting
Work
Evidence
AI involvement reported · Causal attribution alleged · 1 source
4 claims: 4 reported. 5 open questions
People reported harmed
1 person

AI system as recorded: One of the two coding agents the poster runs together, Claude Code and OpenAI Codex; the post does not say which one copied server.js out of the two-week-old archive

What Happened

The restore. The poster writes: "I had asked it to revert some wording it had changed in a privacy policy. To do that it looked around the project, found a .tar.gz in the root, and copied server.js out of it. Reasonable-looking move. The problem is that the archive was a snapshot from two weeks earlier, and the filename gave no hint of that." The agent "didn’t crash anything. It didn’t throw an error. It reported success."

What was lost. "That one cp took out four verified security fixes and an entire moderation API layer. The fixes were ones the same agent had written, tested and deployed about forty minutes earlier in the same session. It overwrote its own work and didn’t notice, because it only diffed the file it cared about." The poster lists the fixes as a fix for an unauthenticated crash, an access-control fix on private rooms, a fix for an unsigned cookie that let a user register against someone else's identity, and session invalidation on password reset, and says of the problems those fixes had closed: "All four were live again for two days and nobody knew."

Discovery and recovery. "Nothing was in git. I found out two days later when an endpoint returned 404 that should not have." Recovery came from "the agents’ own session logs": the poster says Codex keeps rollouts and a thread history and Claude Code keeps a transcript, and "The lost code was sitting in those transcripts as tool-call arguments. I reconstructed the moderation layer from one and confirmed the timeline from the other, including the exact command that did the damage, timestamped."

Which agent. The poster runs both agents: "My Claude quota runs out most days and the ChatGPT subscription sits idle, so handing the heavy reading to Codex is genuinely useful." The post does not state which agent ran the copy.

The poster's response. Replying to a commenter who pointed to git, code review and testing, the poster writes: "I shipped it, so it’s mine", that git was "the actual lesson and the one I had been putting off, through three separate reminders", and that a test suite "would have caught this". The poster adds: "The failure was not an agent writing something bad, it was an agent reverting something good with nothing in place to notice."

Reported harm

The poster says an agent's file restore silently removed four deployed security fixes and a moderation API layer from a live service for two days and cost a fortnight of work, later reconstructed from session transcripts (first-person account, uncorroborated).

Outcome

Resolved

The poster says the moderation layer was reconstructed from one agent's session transcript and the timeline, including the exact command, confirmed from the other; git, a 110-check test suite and a worktree-isolation script for the second agent were adopted afterwards. The poster says the four problems the fixes had closed were "live again for two days and nobody knew".

What remains unknown

  • Which agent, Claude Code or Codex, ran the copy; the post names both as in use.
  • The model and agent versions.
  • When the restore happened; the post of 8 October 2026 says the loss was found two days after it.
  • The service and its users, and whether anyone exploited the two-day absence of the fixes.
  • The poster's country.

What the evidence supports

AI involvement: reported. The poster states that a coding agent, acting on a request to revert wording in a privacy policy, copied server.js out of a two-week-old archive and reported success, and that this copy removed four deployed security fixes, which the agent had itself written, tested and deployed about forty minutes earlier, and a moderation API layer; the poster says the exact command was later found, timestamped, in the agent's session transcript. The agent's copy is the described action and the overwritten, two-day-absent code is its described consequence. Which of the poster's two agents (Claude Code or Codex) ran the copy is not stated. The account is the poster's own and is uncorroborated.

4 claims: 4 reported. What the statuses mean

Reported The poster says an agent, asked to revert wording in a privacy policy, copied server.js out of a .tar.gz archive in the project root that was a two-week-old snapshot, and reported success.

Causal attribution. Poster's account; the agent's command is described from the session transcript the poster read.

  • reddit.com(opens in new tab) supports · English
    'I had asked it to revert some wording it had changed in a privacy policy. To do that it looked around the project, found a `.tar.gz` in the root, and copied `server.js` out of it'; 'the archive was a snapshot from two weeks earlier, and the filename gave no hint of that'; 'It reported success'
Reported The poster says the copy removed four verified security fixes, which the same agent had written, tested and deployed about forty minutes earlier, and an entire moderation API layer, that nothing was in git, and that the loss was found two days later when an endpoint returned 404.

Causal attribution. Poster's account of the loss and its discovery.

  • reddit.com(opens in new tab) supports · English
    'That one `cp` took out four verified security fixes and an entire moderation API layer. The fixes were ones the *same agent* had written, tested and deployed about forty minutes earlier in the same session'; 'Nothing was in git. I found out two days later when an endpoint returned 404 that should not have'
Reported The poster says the lost code was reconstructed from the agents' session transcripts, where it sat as tool-call arguments, and that the four problems the fixes had closed were, in the poster's words, 'live again for two days and nobody knew'.

Causal attribution. Poster's account of the recovery.

  • reddit.com(opens in new tab) supports · English
    'The lost code was sitting in those transcripts as tool-call arguments. I reconstructed the moderation layer from one and confirmed the timeline from the other, including the exact command that did the damage, timestamped'; 'All four were live again for two days and nobody knew'
Reported The poster runs Claude Code and OpenAI Codex together, does not say which agent ran the copy, and in a reply accepts responsibility for shipping without git or tests.

Causal attribution. Poster's own statements; the acting agent is not identified in the post or the reply.

  • reddit.com(opens in new tab) supports · English
    'My Claude quota runs out most days and the ChatGPT subscription sits idle, so handing the heavy reading to Codex is genuinely useful'; 'I shipped it, so it’s mine'; 'The failure was not an agent writing something bad, it was an agent reverting something good with nothing in place to notice'

Sources

1 source inspected. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

Read in English on 2026-10-09: full self-text and the 4 comments retrieved through the arctic_shift archive API by post ID, one of them the poster's reply. The poster handle is not recorded. Applies to s1.

Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.

No source states where the poster or the service is. No court proceedings.

Reviewed for publication 2026-10-09: Published under the public-forum rule as a concrete first-person account of a coding agent restoring a stale file and silently removing deployed security fixes and a moderation layer, with the restore, the loss, the two-day exposure and the recovery attributed to the poster. The acting agent is recorded as unidentified because the post names two agents in use without saying which ran the copy. The poster's handle, the service and the poster's GitHub account are not named.

People described

A developer running a live service with a moderation layer who uses two coding agents; no name, country or service is recorded

People reported harmed in this case

1 person

1 AI participant · 0 other people harmed

One person counted: the poster, whose deployed work the agent overwrote. Users of the service during the two days the fixes were absent are not described as harmed and are not counted.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). Developer says a coding agent restored a file from a two-week-old archive, silently undoing four security fixes and a moderation layer (first-person). AI incidents. https://nope.net/incidents/2026-coding-agent-restored-server-file-from-two-week-old-archive-undoing-security-fixes-and-moderation-layer-first-person

BibTeX

@misc{2026_coding_agent_restored_server_file_from_two_week_old_archive_undoing_security_fixes_and_moderation_layer_first_person,
  title = {Developer says a coding agent restored a file from a two-week-old archive, silently undoing four security fixes and a moderation layer (first-person)},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2026-coding-agent-restored-server-file-from-two-week-old-archive-undoing-security-fixes-and-moderation-layer-first-person}
}

Related cases

Low Claude Code

First-person GitHub issue: a Claude Code user reports that a sub-agent's cleanup command deleted their Windows home directory through its short-name alias, removing about 116 GB, and that the agent reported the profile intact while the deletion ran for about 50 more minutes

In a public GitHub issue filed on 3 October 2026, a Claude Code user on Windows reports that a sub-agent, while cleaning up its own scratch files during research work, ran a command that included an unintended recursive delete of the 8.3 short-name alias of their home folder. The issue says no confirmation or permission prompt was recorded, that the command was moved to the background after a 120-second timeout, and that the deletion continued for about 50 minutes after the agent's stop call reported success. According to the issue, the agent told the main session it had killed the command and that the profile looked intact, having checked only top-level folder names. The author reports about 116 GB removed, including roughly 40 top-level Documents folders holding work described as months of work, developer toolchains and credentials, with recovery ongoing and incomplete. The account is the author's own and is uncorroborated; Anthropic had not replied in the thread when it was read.

Medium Cursor coding agent

Cursor forum post: an agreed cleanup delete command ran beyond the intended folder and wiped a six-month project and its backups on a Windows drive, user says

In a bug report posted to the Cursor community forum on 3 October 2026, a user says that during a clean-up of a .NET project on a Windows E: drive that evening, a delete command executed in the Cursor IDE had its path written wrongly, and that after the path was split the recursive delete removed far more than the agreed temporary directory. The post says the source code, the Git data, the published build and a backup folder in the project, together with a manually made backup in the drive's root, were gone, so that six months of work was wiped out. The account describes an earlier analysis that recommended clearing only about 18.5 GB of compilation temporaries and the user agreeing to that batch. Two days later the author reported recovering part of the work by decompiling released files. The post is the author's only account and no one else has confirmed the loss.

Medium Google Antigravity (suspected)

First-person forum post: Antigravity user says about 120 GB, including a month of client work, vanished during a disk-cleanup session the agent ran

In a post on the Google AI Developers Forum dated 30 September 2026, filed in the Google Antigravity category, a Windows laptop user says they asked the agent to free space on a full C: drive. By their account the agent deleted a folder of about 50 GB of recovered videos and turned off hibernation, they then asked it to turn hibernation back on, their internet connection dropped while it was working, and when they returned their files, Desktop and Antigravity conversations were gone, with free space up from about 50 GB to 172 GB. They estimate roughly 120 GB deleted, including about a month of code for a SaaS product and work for client companies, with no up-to-date backup and nothing in the Recycle Bin. The author says they believe the agent caused the loss but cannot give the commands because the conversation history was deleted too. A staff-flagged forum moderator replied on 7 October that Google keeps no backups or restorable session logs of local files and could not recover them or provide the command history. The account is uncorroborated.

Low Claude

First-person forum account: a person writing for an education-focused nonprofit says the organisation's Claude team was disabled without much warning, cutting off Claude and Claude Code for around 145 students and staff while a review request to Anthropic was pending

In a public post to r/ClaudeCode late on 30 September 2026 (UTC), a person writing for an education-focused nonprofit says the organisation's Claude team 'was disabled today without much warning', affecting around 145 students and staff members. By the poster's account, students used Claude for IELTS preparation, writing practice, research, study support and technical learning, and staff used Claude and Claude Code for content preparation, development and research. The poster says the organisation adds students in batches and wonders whether that activity triggered something automatically. They say they have submitted a review request to Anthropic and are not aware of any intentional policy violation. In a reply they say direct messages to three people went unanswered. Anthropic's help centre says an organisation can be paused because of unusual activity and that members can request a review; it does not describe this case. Whether an automated system made the decision is not known. The account is uncorroborated.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.