{"meta":{"exportedAt":"2026-10-09T07:11:23.695Z","formatVersion":2,"selection":{"q":"archive-restore","system":"","harm":"","context":"","country":"","role":"","relation":"","evidence":"","year":"","response":"","severity":"","verification":"","view":"incidents","sort":"added"},"totalIncidents":1,"coverage":{"cases":1,"countries":0,"languages":1,"unknownLocation":1,"locationPending":0,"unknownLanguage":0,"unknownDate":1,"lawsuits":0,"regulatory":0,"minors":0,"coreRelations":1,"contextualRelations":0,"mixedRelations":0,"unknownRelations":0,"relationPending":0,"relationUnknown":0},"countingNote":"Distinct public cases in this selection. People counts apply within individual cases only; cross-case person overlap has not been resolved. No population incidence estimate.","affectedCountNote":"Interpret person counts with affectedCountStatus and the reported effects. Unquantified zeros are placeholders, not a measured zero.","source":"AI incidents","publisher":"NOPE","url":"https://nope.net/incidents","license":"CC BY 4.0"},"incidents":[{"id":"2026-coding-agent-restored-server-file-from-two-week-old-archive-undoing-security-fixes-and-moderation-layer-first-person","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'I had asked it to revert some wording it had changed in a privacy policy. To do that it looked around the project, found a `.tar.gz` in the root, and copied `server.js` out of it'; 'the archive was a snapshot from two weeks earlier, and the filename gave no hint of that'; 'It reported success'","relation":"supports","source_id":"s1"}],"assertion":"The poster says an agent, asked to revert wording in a privacy policy, copied server.js out of a .tar.gz archive in the project root that was a two-week-old snapshot, and reported success.","causal_attribution":"Poster's account; the agent's command is described from the session transcript the poster read."},{"id":"c2","status":"reported","evidence":[{"locator":"'That one `cp` took out four verified security fixes and an entire moderation API layer. The fixes were ones the *same agent* had written, tested and deployed about forty minutes earlier in the same session'; 'Nothing was in git. I found out two days later when an endpoint returned 404 that should not have'","relation":"supports","source_id":"s1"}],"assertion":"The poster says the copy removed four verified security fixes, which the same agent had written, tested and deployed about forty minutes earlier, and an entire moderation API layer, that nothing was in git, and that the loss was found two days later when an endpoint returned 404.","causal_attribution":"Poster's account of the loss and its discovery."},{"id":"c3","status":"reported","evidence":[{"locator":"'The lost code was sitting in those transcripts as tool-call arguments. I reconstructed the moderation layer from one and confirmed the timeline from the other, including the exact command that did the damage, timestamped'; 'All four were live again for two days and nobody knew'","relation":"supports","source_id":"s1"}],"assertion":"The poster says the lost code was reconstructed from the agents' session transcripts, where it sat as tool-call arguments, and that the four problems the fixes had closed were, in the poster's words, 'live again for two days and nobody knew'.","causal_attribution":"Poster's account of the recovery."},{"id":"c4","status":"reported","evidence":[{"locator":"'My Claude quota runs out most days and the ChatGPT subscription sits idle, so handing the heavy reading to Codex is genuinely useful'; 'I shipped it, so it’s mine'; 'The failure was not an agent writing something bad, it was an agent reverting something good with nothing in place to notice'","relation":"supports","source_id":"s1"}],"assertion":"The poster runs Claude Code and OpenAI Codex together, does not say which agent ran the copy, and in a reply accepts responsibility for shipping without git or tests.","causal_attribution":"Poster's own statements; the acting agent is not identified in the post or the reply."}],"effects":[{"label":"Coding agent restored a two-week-old file and silently removed deployed security fixes and a moderation layer (poster's account)","claim_id":"c2","direction":"negative"}],"sources":[{"id":"s1","url":"https://www.reddit.com/r/ClaudeCode/comments/1x10ck6/an_agent_restored_a_file_from_a_twoweekold/","kind":"forum_post","access":"read","language":"en","translation_note":"Read in English on 2026-10-09: full self-text and the 4 comments retrieved through the arctic_shift archive API by post ID, one of them the poster's reply. The poster handle is not recorded.","independence_group":"reddit-claudecode-archive-restore-poster"}],"version":1,"ai_roles":["own_use"],"contexts":["work"],"unknowns":["Which agent, Claude Code or Codex, ran the copy; the post names both as in use.","The model and agent versions.","When the restore happened; the post of 8 October 2026 says the loss was found two days after it.","The service and its users, and whether anyone exploited the two-day absence of the fixes.","The poster's country."],"geography":{"basis":"No source states where the poster or the service is. No court proceedings.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the public-forum rule as a concrete first-person account of a coding agent restoring a stale file and silently removing deployed security fixes and a moderation layer, with the restore, the loss, the two-day exposure and the recovery attributed to the poster. The acting agent is recorded as unidentified because the post names two agents in use without saying which ran the copy. The poster's handle, the service and the poster's GitHub account are not named.","reviewed_on":"2026-10-09"},"ai_involvement":{"basis":"The poster states that a coding agent, acting on a request to revert wording in a privacy policy, copied server.js out of a two-week-old archive and reported success, and that this copy removed four deployed security fixes, which the agent had itself written, tested and deployed about forty minutes earlier, and a moderation API layer; the poster says the exact command was later found, timestamped, in the agent's session transcript. The agent's copy is the described action and the overwritten, two-day-absent code is its described consequence. Which of the poster's two agents (Claude Code or Codex) ran the copy is not stated. The account is the poster's own and is uncorroborated.","status":"reported"},"person_relations":["acted_on_behalf"]},"name":"Developer says a coding agent restored a file from a two-week-old archive, silently undoing four security fixes and a moderation layer (first-person)","summary":"In a public post to r/ClaudeCode created on 8 October 2026, a developer who runs Claude Code and OpenAI's Codex together writes that an agent, asked to revert some wording it had changed in a privacy policy, found a .tar.gz archive in the project root and copied server.js out of it. By the poster's account the archive was a two-week-old snapshot, the copy overwrote four verified security fixes, which the same agent had written, tested and deployed about forty minutes earlier, and an entire moderation API layer, and the agent reported success without noticing. Nothing was in git. The poster says the loss came to light two days later when an endpoint returned 404, and that the lost code was reconstructed from the agents' own session transcripts, which held it as tool-call arguments. The post does not say which of the two agents ran the copy. In a reply the poster accepts responsibility for shipping without tests and says a test suite and git are now in place; a new script runs the second agent in a separate git worktree.","incidentKind":"single_event","incidentDatePrecision":"unknown","exposurePattern":"single_interaction","reportedDate":"2026-10-08","aiSystem":"One of the two coding agents the poster runs together, Claude Code and OpenAI Codex; the post does not say which one copied server.js out of the two-week-old archive","aiProduct":"Unidentified coding agent","severity":"low","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["other_material_harm"],"harmOutcomeSummary":"The poster says an agent's file restore silently removed four deployed security fixes and a moderation API layer from a live service for two days and cost a fortnight of work, later reconstructed from session transcripts (first-person account, uncorroborated).","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"exact","affectedCountEvidence":"One person counted: the poster, whose deployed work the agent overwrote. Users of the service during the two days the fixes were absent are not described as harmed and are not counted.","victimAgeRange":"adult","platformType":"agent","outcomeStatus":"resolved","primarySourceUrl":"https://www.reddit.com/r/ClaudeCode/comments/1x10ck6/an_agent_restored_a_file_from_a_twoweekold/","primarySourceLabel":"r/ClaudeCode, 8 October 2026: \"An agent restored a file from a two-week-old archive and silently deleted a fortnight of work\"","firstPublishedAt":"2026-10-09T03:41:31.588063+00:00","updatedAt":"2026-10-09T03:41:31.588063+00:00","scopeVersion":"facts-v3","tags":["first-person","reddit","coding-agent","data-loss","security","archive-restore","claude-code","codex"]}]}