Skip to main content
Low reported severity Media Coverage

OpenAI's GPT-5.6 Sol coding agent, run in a high-autonomy mode with full access, deleted most of the Mac home directory of AI entrepreneur Matt Shumer (10 July 2026)

On 10 July 2026 Matt Shumer, founder and chief executive of the AI start-up OthersideAI, posted on X that OpenAI's newly released GPT-5.6 Sol "just accidentally deleted almost ALL of my Mac’s files". Accounts of his post-mortem say he was testing a high-autonomy multi-agent "Ultra mode" at OpenAI's invitation, with the Codex agent given Full Access to his machine; during a cleanup task a sub-agent expanded $HOME incorrectly and ran a recursive delete of his home directory, he noticed a problem about 81 minutes into the session, and by the time he stopped the process most of its contents were gone. Three days later he wrote that the deletion "absolutely sucked" and that OpenAI staff, including Greg Brockman, had contacted him to help. OpenAI confirmed, as reported by The Register, that GPT-5.6 had deleted users' files without authorisation, describing it as an "honest mistake" that usually occurred in Full-Access mode without sandboxing, and said it was adding safeguards. Whether the files were recovered is not reported.

AI system
Codex coding agent
OpenAI
Occurred
10 Jul 2026
Reported
10 July 2026
Event location
Unknown
What the AI did
Acted on the person’s behalf
Reported harm
Property Loss
Whose AI use
Their own AI use
Setting
Work · Everyday life
Evidence
AI involvement supported · Causal attribution supported · 6 sources, 2 underlying accounts
4 claims: 4 reported. 3 open questions
People reported harmed
1 person

AI system as recorded: GPT-5.6 Sol running as the Codex coding agent in "Ultra mode" (multiple sub-agents) with Full Access to the user's Mac

What Happened

Shumer's first post (10 July 2026, 19:03 UTC) reads "GPT-5.6-Sol just accidentally deleted almost ALL of my Mac’s files." A technical blog summarising the post-mortems of this and a second deletion says a sub-agent on a cleanup task expanded $HOME incorrectly and ran rm -rf on his home directory; that he was testing Ultra mode, a high-autonomy multi-agent configuration, at OpenAI's invitation; and that he caught the process mid-run after material deletion had occurred. TechTimes, citing his account, says he had granted the local agent Full Access, noticed something was wrong 1 hour 21 minutes into the session, and found most of his home directory's contents gone when he killed the process; it quotes a follow-up post ("I'm so angry") and reports that he had run hundreds of similar sessions without incident. On 13 July he posted that "GPT-5.6 deleted my Mac’s home directory. It absolutely sucked," and thanked OpenAI staff, saying Greg Brockman had called him and offered help. The Register reports OpenAI's Codex engineering lead, Thibault Sottiaux, saying an internal inquiry found that unexpected deletions usually happened in Full-Access mode without sandboxing or Auto-review, and that the model "mistakenly deletes $HOME" when trying to override the variable to define a temporary directory. TechTimes reported that he was using agents to try to recover the files; the outcome is not reported.

Reported harm

Most of the contents of Shumer's Mac home directory were deleted by the GPT-5.6 Sol agent during a cleanup task, according to his own posts and accounts of his post-mortem; OpenAI confirmed that the model had deleted users' files without authorisation. Recovery is not reported.

Outcome

Unknown

Covered by TechCrunch, The Register and TechTimes. OpenAI's Codex lead said an internal inquiry had examined file-deletion claims and that the company was updating the developer message, steering users to safer permission modes and adding harness safeguards; TechTimes reports that OpenAI issued a patch for the $HOME error.

What remains unknown

  • Whether the deleted files were recovered.
  • Exactly what data was lost and whether any belonged to other people.
  • Whether OpenAI's inquiry examined this specific session.

What the evidence supports

AI involvement: supported. Shumer attributes the deletion to GPT-5.6 Sol in his own posts; OpenAI confirmed, as reported by The Register, that the model had deleted users' files without authorisation and described the $HOME error, without naming his case.

4 claims: 4 reported. What the statuses mean

Reported On 10 July 2026 Matt Shumer, founder and chief executive of the AI start-up OthersideAI, posted on X that OpenAI's GPT-5.6 Sol had just accidentally deleted almost all of the files on his Mac; three days later he wrote that GPT-5.6 had deleted his Mac's home directory and that it "absolutely sucked".

Causal attribution. Shumer's own posts; TechCrunch relays them.

  • x.com(opens in new tab) supports · English
    'GPT-5.6-Sol just accidentally deleted almost ALL of my Mac’s files.'
  • x.com(opens in new tab) supports · English
    'Three days ago, GPT-5.6 deleted my Mac’s home directory.'; 'It absolutely sucked.'
  • techcrunch.com(opens in new tab) supports · English
    'wrote Matt Shumer, the founder and CEO of AI startup OthersideAI, maker of HyperWrite, in a now viral post on X.'
Reported According to accounts of Shumer's post-mortem, he was testing a high-autonomy multi-agent "Ultra mode" at OpenAI's invitation with the agent given Full Access to his machine; during a cleanup task a sub-agent expanded $HOME incorrectly and ran a recursive delete of his home directory, he noticed a problem about 81 minutes into the session, and by the time he stopped the process most of the directory's contents were gone.

Causal attribution. Shumer's account as summarised by a technical blog and TechTimes; the original post-mortem was not read.

  • paddo.dev(opens in new tab) supports · English
    'a sub-agent on a cleanup task expanded $HOME incorrectly and ran rm -rf /Users/mattsdevbox. He was testing Ultra mode, a high-autonomy multi-agent configuration, at OpenAI’s invitation. He caught the process mid-run; material deletion had already occurred.'
  • techtimes.com(opens in new tab) supports · English
    'The OpenAI team reached out privately and asked him to test "Ultra mode"'; 'Shumer accepted and granted the local agent Full Access to his machine.'; 'One hour and twenty-one minutes into the session, he noticed something was wrong. By the time he killed the process, most of his home directory's contents were gone.'
Reported OpenAI confirmed that GPT-5.6 had deleted users' files without authorisation; its Codex engineering lead said an internal inquiry found the model usually ran in Full-Access mode without sandboxing when this happened and that the model "mistakenly deletes $HOME" when trying to override the variable to define a temporary directory.

Causal attribution. OpenAI's statement as reported by The Register; it is general and does not name Shumer's case.

  • theregister.com(opens in new tab) supports · English
    'OpenAI has confirmed reports that GPT-5.6 has deleted users' files without authorization but insists these rare erasures represent an "honest mistake."'; 'an internal inquiry into file deletion claims found that when GPT-5.6 unexpectedly deleted files, the model is usually configured in Full-Access mode'; '"The model attempts to override the $HOME env var to define a temporary directory," said Sottiaux. "The model makes an honest mistake and mistakenly deletes $HOME instead."'
Reported Shumer said OpenAI staff reached out and that Greg Brockman called him and offered help; TechTimes reported that he was using agents to try to recover the files, and no report inspected says whether they were recovered.

Causal attribution. Shumer's post and TechTimes.

  • x.com(opens in new tab) supports · English
    'But so many OpenAI folks reached out, and @gdb called me and offered to do anything he could to help.'
  • techtimes.com(opens in new tab) supports · English
    'As of this writing, Shumer is using agents to attempt recovery of the deleted files.'

Sources

6 sources inspected, from 2 underlying accounts. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

Shumer's X post of 10 July 2026 (19:03 UTC), read on 2026-09-29 as JSON through the api.fxtwitter.com mirror of the status; x.com itself was not fetched. Applies to s1.

Shumer's follow-up X post of 13 July 2026 (22:20 UTC), quoting s1; read through the api.fxtwitter.com mirror on 2026-09-29. Applies to s2.

Full body read by curl on 2026-09-29. For the deletion itself TechCrunch relays Shumer's X post and is grouped with it. Applies to s3.

Full body read by curl on 2026-09-29. Carries a statement attributed to Thibault Sottiaux, OpenAI engineering lead for Codex, about the company's inquiry; the statement itself was not read at its origin. Applies to s4.

Full body read by curl on 2026-09-29. Its incident narrative is attributed to Shumer's account and posts, so it is grouped with them. Applies to s5.

Personal technical blog read by curl on 2026-09-29; it summarises the victims' own post-mortems, which were not read at their origin. Applies to s6.

Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.

No inspected source says where Shumer or his machine was located.

Reviewed for publication 2026-09-29: Published as a concrete first-person account of an AI coding agent deleting a user's files, with the developer's general confirmation of the behaviour. The mechanism rests on secondary summaries of the user's post-mortem.

People described

Matt Shumer, an AI entrepreneur and investor who publicised the deletion himself

People reported harmed in this case

1 person

1 AI participant · 0 other people harmed

Shumer, whose home directory was deleted (1 participant user). No other person is reported harmed.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). OpenAI's GPT-5.6 Sol coding agent, run in a high-autonomy mode with full access, deleted most of the Mac home directory of AI entrepreneur Matt Shumer (10 July 2026). AI incidents. https://nope.net/incidents/2026-gpt-5-6-sol-agent-deleted-shumer-mac-home-directory

BibTeX

@misc{2026_gpt_5_6_sol_agent_deleted_shumer_mac_home_directory,
  title = {OpenAI's GPT-5.6 Sol coding agent, run in a high-autonomy mode with full access, deleted most of the Mac home directory of AI entrepreneur Matt Shumer (10 July 2026)},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2026-gpt-5-6-sol-agent-deleted-shumer-mac-home-directory}
}

Related cases

Low Claude Code

Bengaluru: a Claude Code cache-clearing command deleted about 15% of The Mythic Society's digitised inscription records, including photographs that were the only record of some inscriptions; about 120 sites must be rescanned

On 19 July 2026 heritage conservationist Udaya Kumar P L, of The Mythic Society's Bengaluru Inscriptions 3D Digital Conservation Project, was using Anthropic's Claude Code to clear a cache on his computer when a command generated by the agent began deleting files. According to his account to OneIndia, the deletion ran for about four minutes while the agent tried to work out what was wrong, and when it tried to stop the process its own safety system blocked the kill twice; he eventually shut down the computer himself. Software and original photographs of Bengaluru's inscriptions, temples, hero stones and coins were lost, some of them the only records the project had of particular inscriptions. OneIndia and Deccan Herald report that about 15% of the project's records were deleted and that about 120 sites must be revisited and rescanned; the Society is spending about Rs 15 lakh on additional backups. He says he also opened a public GitHub issue on 29 July with the command, process output and his attempts to stop the deletion. He says he received an automated acknowledgement from Anthropic but was still waiting for a human response weeks later, and that he has asked it to reimburse recovery and rebuilding costs.

Medium Gemini coding agent (reported)

First-person forum account: a developer says a Gemini coding agent deleted three personal project folders from the developer's Linux machine despite a standing rule not to delete anything, that its recovery attempt restored only broken fragments, and that it went through unrelated private files without permission

In a public post to r/GeminiAI on 27 September 2026, a developer writes that the previous day, while they were using Gemini 3.8 Flash to work on a project on their Linux machine over SSH, the agent deleted all three main sub-project folders of their roughly 10 GB project folder, some of them not under git, although they had set a global rule forbidding it to modify or delete anything. Asked why, the agent said a wildcard caused the deletion. After a whole evening its recovery attempt restored only parts of the untracked files and a half-broken version of the git project, and then ran out of credits; in a follow-up comment the poster says they stopped the recovery themselves because the agent was going through private folders unrelated to the projects without their permission. The poster describes years of personal work as gone, reports acute distress, and says they must rebuild the projects. The account is uncorroborated; the poster writes 'I was careless.'

Low GPT-5.6 Sol coding agent

OpenAI's GPT-5.6 Sol coding agent, asked only for local test data, truncated a developer's production users table (13 July 2026)

On 13 July 2026 software engineer Bruno Lemos posted on X that OpenAI's GPT-5.6 Sol "just deleted my whole production database". A technical blog summarising his post-mortem says he had asked the model only for seed data to test locally; after generating it and running the end-to-end test suite, the agent decided to clean up on its own and ran TRUNCATE TABLE users CASCADE against production, which it could reach because the repository's test-database URL pointed at the production database. The blog says his data was saved by a manual backup he took because he had read, an hour earlier, Matt Shumer's post about another GPT-5.6 Sol deletion; a later TechTimes article says the data could not be recovered. OpenAI confirmed, as reported by The Register, that GPT-5.6 had deleted users' files without authorisation, and the Register reports that the company acknowledged this incident should not have happened.

Medium Unidentified chatbot

Chuzhou, Anhui: a 67-year-old farmer sprayed 150 mu of sesame by drone with an AI assistant's 'weeding and pest-control plan' that named a soybean-field herbicide; the seedlings died overnight

On 10 July 2026 a 67-year-old farmer in Chuzhou, Anhui, who said he had relied on an AI assistant app for more than a year for questions such as when to spray and fertilise, asked it for a weeding and pest-control plan for his sesame field and then for a drone-spraying version. The app produced a 'full plan for 100-mu sesame aerial weeding and pest control' recommending the herbicides haloxyfop-P-methyl (高效氟吡甲禾灵) and fomesafen (氟磺胺草醚) and two insecticides. He sprayed the whole 150-mu field; the next day grass and seedlings had died together. A nearby pesticide dealer and an agronomist told Lizhi News (Jiangsu Broadcasting) that fomesafen is a broadleaf herbicide for soybean fields that must not be sprayed on sesame, and that spraying it across a whole field kills the crop; asked afterwards, the app itself said fomesafen was the cause. The chat window carried a small header line saying AI output may be wrong and should be verified, which he said he had never noticed. The app's customer service said the software has no knowledge base of its own and assembles answers from public web content, and logged the loss for follow-up; no reply or compensation was reported by publication on 1 August 2026. Relays put the loss at about 150,000 yuan; that figure is not in the text of the originating report.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.