{"meta":{"exportedAt":"2026-10-10T07:14:00.893Z","formatVersion":2,"selection":{"q":"backups","system":"","harm":"","context":"","country":"","role":"","relation":"","evidence":"","year":"","response":"","severity":"","verification":"","view":"incidents","sort":"added"},"totalIncidents":8,"coverage":{"cases":8,"countries":1,"languages":1,"unknownLocation":7,"locationPending":0,"unknownLanguage":0,"unknownDate":1,"lawsuits":0,"regulatory":0,"minors":0,"coreRelations":8,"contextualRelations":0,"mixedRelations":0,"unknownRelations":0,"relationPending":0,"relationUnknown":0},"countingNote":"Distinct public cases in this selection. People counts apply within individual cases only; cross-case person overlap has not been resolved. No population incidence estimate.","affectedCountNote":"Interpret person counts with affectedCountStatus and the reported effects. Unquantified zeros are placeholders, not a measured zero.","source":"AI incidents","publisher":"NOPE","url":"https://nope.net/incidents","license":"CC BY 4.0"},"incidents":[{"id":"2026-claude-code-opus-5-5-hands-free-skip-permissions-session-deleted-developer-windows-c-drive-first-person","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'Opus 5.5 just deleted my entire fucking C drive'; 'Thank GOD I have daily backups running to my Synology NAS'","relation":"supports","source_id":"s1"},{"locator":"'A developer says Anthropic’s most powerful model wiped his computer’s entire C: drive while working on its own, and only his nightly backups saved him'","relation":"context","source_id":"s4"}],"assertion":"The developer says Claude Code running Opus 5.5 deleted the entire C drive of the developer's machine, and that daily backups to a Synology NAS saved the data.","causal_attribution":"The developer's own account, with a screenshot attached to the first post showing an analysis of unstated authorship that quotes the command; MadRobot says the account \"hasn’t been independently checked\"."},{"id":"c2","status":"reported","evidence":[{"locator":"'I have many multi-hour long sessions running at any given point in time (deliberately) on a hands free basis'; 'I've run sessions on this machine with the --dangerously-skip-permissions tag since Opus 4.6 (probably sooner tbh) without this kind of issue surfacing'; 'For a simple powershell syntax mangling issue to cause such a catastrophic problem (on opus 5.5 nonetheless) is wild to me'","relation":"supports","source_id":"s2"},{"locator":"image attached to the post: 'It was one of your own Claude Code sessions'; 'It was running in bypass-permissions mode'; 'The quoting is wrong for Windows PowerShell 5.1'; 'a bare \\ means the root of drive C:'","relation":"supports","source_id":"s1"}],"assertion":"The developer says the sessions run for hours unattended with the --dangerously-skip-permissions flag, as they had since Opus 4.6 without such an issue, and attributes the deletion to a PowerShell syntax mangling issue, and a screenshot attached to the first post quotes a folder-removal command whose quoting Windows PowerShell 5.1 resolved to the root of drive C:.","causal_attribution":"The developer's own explanation of the session setup and of the cause; the screenshot attached to the first post quotes the command and explains the quoting error, and its author is not stated."},{"id":"c3","status":"reported","evidence":[{"locator":"'I have built the appropriate deterministic safeguards to prevent this from happening again & have been able to recover 98% of my data'; 'It's nobodies fault but I'm own'","relation":"supports","source_id":"s2"}],"assertion":"The developer says 98% of the data has been recovered and that deterministic safeguards have been built, and accepts the fault as the user's own.","causal_attribution":"The developer's own account of the recovery."},{"id":"c4","status":"documented","evidence":[{"locator":"'This is the reason why we recommend (and default to) auto mode for permissions. It almost certainly would have caught this, is there a reason you aren’t using it?'","relation":"supports","source_id":"s3"},{"locator":"'Boris Cherny, who leads Claude Code at Anthropic, replied that this is exactly why the company recommends its newer permissions setting'","relation":"context","source_id":"s4"}],"assertion":"Anthropic's head of Claude Code replied publicly that the company recommends and defaults to auto mode for permissions, which \"almost certainly would have caught this\", and asked why the developer was not using it.","causal_attribution":"The reply is the cited record itself. It is a vendor response and does not confirm or dispute the deletion; Anthropic made no formal statement."},{"id":"c5","status":"reported","evidence":[{"locator":"image attached to the post: 'It wasn't admin. That's why Program Files, Windows and the other accounts survived'; 'A safety check had already blocked an earlier version of the cleanup at 3:52 PM. The session then retried it as a separate cmd /c rmdir command that the check didn't catch'","relation":"supports","source_id":"s1"}],"assertion":"The screenshot attached to the developer's first post says the session was not running as administrator, so Program Files, Windows and other accounts' files survived, and that a safety check had blocked an earlier version of the cleanup before the session retried it as a separate command.","causal_attribution":"Analysis of unstated authorship posted by the developer; the logs it drew on were not published."}],"effects":[{"label":"Coding agent's mis-quoted folder-removal command ran against the root of the Windows C: drive during an unattended session; 98% recovered from backups (developer's account)","claim_id":"c1","direction":"negative"}],"sources":[{"id":"s1","url":"https://x.com/PerceptualPeak/status/2107621483392446572","kind":"social_media_post","access":"read","language":"en","translation_note":"Read in English on 2026-10-09 through the fxtwitter API copy of the post (full text, 1,028,548 views and 855 replies at fetch time). Replies in the thread other than those cited were not retrieved. Re-read from the saved copy on 2026-10-10. The attached image (a screenshot of text, media.photos[0] in the fxtwitter copy) was read; its command path, which carries the developer's Windows account name and a project folder, is not reproduced.","independence_group":"x-developer-thread"},{"id":"s2","url":"https://x.com/PerceptualPeak/status/2107720127181738135","kind":"social_media_post","access":"read","language":"en","translation_note":"Read in English on 2026-10-09 and re-read from the saved copy on 2026-10-10 through the fxtwitter API copy (full text). The developer's reply to Boris Cherny.","independence_group":"x-developer-thread"},{"id":"s3","url":"https://x.com/bcherny/status/2107695244238324001","kind":"social_media_post","access":"read","language":"en","translation_note":"Read in English on 2026-10-09 and re-read from the saved copy on 2026-10-10 through the fxtwitter API copy (full text). Reply by Anthropic's head of Claude Code to the developer's first post.","independence_group":"anthropic-claude-code-lead"},{"id":"s4","url":"https://madrobot.blog/2026/10/07/claude-opus-5-5-deleted-c-drive-claude-code-auto-mode-boris-cherny/","kind":"news_blog","access":"read","language":"en","translation_note":"Read in English on 2026-10-09 and re-read from the saved copy on 2026-10-10 (direct fetch, 200). The blog relays the X thread and the Cherny reply and adds Anthropic's published auto-mode figures; it reports no independent checking of the account.","independence_group":"x-developer-thread"}],"version":1,"ai_roles":["own_use"],"contexts":["work","everyday_life"],"unknowns":["The developer's country.","The author of the analysis in the attached screenshot and the logs it drew on; which files were deleted, since the screenshot says Program Files, Windows and other accounts survived while the posts say the entire C drive.","The Claude Code version and the 2% of data not recovered.","Whether Anthropic investigated the session beyond the public reply.","The developer's local date at the time of the deletion; the first post was made at 23:58 UTC on 6 October 2026."],"geography":{"basis":"No source states where the developer is; the X profile and the blog give no location. No court proceedings.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the public-forum rule as a concrete first-person account of a coding agent deleting the user's system drive during an unattended session, with the deletion, the session setup and the recovery attributed to the developer and the vendor's public reply recorded. The source handle appears only in the source URLs; the developer is not named in the record. The AI contribution rests on the developer's statement that the agent's mangled PowerShell command deleted the drive and on the screenshot the developer attached, which quotes the command; the author of that analysis is not stated.","reviewed_on":"2026-10-10"},"ai_involvement":{"basis":"The developer states that Claude Code running Opus 5.5 deleted the entire C drive during a hands-free session started with the --dangerously-skip-permissions flag, and attributes the deletion to a mangled PowerShell command the agent ran; a screenshot the developer attached quotes the rmdir command and attributes the drive-root deletion to a Windows PowerShell 5.1 quoting error (author of the analysis not stated); the agent's own command is the described action and the drive deletion is its described consequence. Anthropic's head of Claude Code replied by recommending auto mode, which the reply said would almost certainly have caught the command; the reply responds to the account without confirming or disputing the deletion. The connection between the agent's action and the loss rests on the developer's own statements, and the logs behind the attached analysis have not been published.","status":"reported"},"person_relations":["acted_on_behalf"]},"name":"Developer says a hands-free Claude Code session on Opus 5.5 deleted the entire Windows C: drive; 98% recovered from daily backups (first-person, X)","summary":"In X posts of 6 and 7 October 2026, a developer writes that Claude Code running Anthropic's Opus 5.5 model \"just deleted my entire fucking C drive\" during a hands-free session, and that daily backups to a NAS saved the data. In a follow-up the developer says the sessions run for hours unattended with the --dangerously-skip-permissions flag, as they had since Opus 4.6 without such an issue, attributes the deletion to \"a simple powershell syntax mangling issue\", says 98% of the data has been recovered and that deterministic safeguards have since been built, and accepts the fault as the user's own while arguing that the harness should prevent such a command natively. The head of Claude Code at Anthropic replied that the company recommends and defaults to auto mode for permissions, which \"almost certainly would have caught this\"; the developer answered that auto mode had felt like babysitting for long unattended sessions. The account is the developer's own. The first post carries a screenshot of a text analysis addressed to the developer, whose author is not stated; it says the session was a Claude Code session in bypass-permissions mode that tried to remove two leftover git worktree folders, quotes the removal command, explains that Windows PowerShell 5.1 read its quoting so that the path became the root of drive C:, and says the session was not running as administrator, so Program Files, Windows and other accounts' files survived. MadRobot wrote that the developer had not shared a command log or screenshots showing what ran.","incidentDate":"2026-10-06","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"single_interaction","reportedDate":"2026-10-06","aiSystem":"Claude Code (Anthropic's coding agent) running the Claude Opus 5.5 model in a multi-hour hands-free session started with the --dangerously-skip-permissions flag on a Windows machine, where the developer says a mangled PowerShell command deleted the C: drive, per the developer's posts and the screenshot attached to the first post","aiProduct":"Claude Code (reported)","severity":"low","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["property_loss","other_material_harm"],"harmOutcomeSummary":"The developer says the agent deleted the entire C: drive of a Windows machine during an unattended session; the developer reports recovering 98% of the data from daily backups, with the remaining loss and the recovery effort unquantified; the screenshot the developer attached says the session was not running as administrator and that Program Files, Windows and other accounts survived (first-person account, uncorroborated).","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"exact","affectedCountEvidence":"One person counted: the developer who ran the session and whose drive was deleted. The thread's view count is an audience figure and is not counted.","victimAgeRange":"unknown","platformType":"agent","outcomeStatus":"resolved","primarySourceUrl":"https://x.com/PerceptualPeak/status/2107621483392446572","primarySourceLabel":"Developer's X post, 6 October 2026: \"Opus 5.5 just deleted my entire ... C drive\"","firstPublishedAt":"2026-10-10T03:12:02.186995+00:00","updatedAt":"2026-10-10T03:12:02.186995+00:00","scopeVersion":"facts-v3","tags":["first-person","x-twitter","coding-agent","data-loss","windows","skip-permissions","claude-code","backups"]},{"id":"2026-cursor-agent-cleanup-delete-command-split-path-wiped-six-month-project-and-backups-windows-drive-first-person-forum","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'On the evening of October 3, 2026'; 'only clear the compilation temporary directory, approximately 18.5 GB'; 'agreeing to this batch'; 'Subsequently, a command had the wrong path written'; 'After the path was split, far more than just that temporary directory was deleted'","relation":"supports","source_id":"s1"}],"assertion":"The post reports that on the evening of 3 October 2026 the user agreed to a clean-up limited to about 18.5 GB of compilation temporaries after an analysis that said to leave the backups, source code, publish folder and Git untouched, that a delete command was then written with the wrong path, and that after the path was split the recursive delete removed far more than the agreed temporary directory.","causal_attribution":"The post attributes the command to the AI in the Cursor IDE: 'AI executed the rmdir command'."},{"id":"c2","status":"reported","evidence":[{"locator":"'resulting in the project of 6 months being wiped out'; 'you manually made in the root directory of the E drive'; 'The entire hard drive was not formatted, but your six months of engineering and manual backups were cleared by this command'","relation":"supports","source_id":"s1"}],"assertion":"The post reports that the project's source code, Git data, publish and backup folders and a manually made backup in the drive root were gone, that six months of engineering and manual backups were cleared by the command, and that the drive was not formatted.","causal_attribution":"User's account; uncorroborated."},{"id":"c3","status":"reported","evidence":[{"locator":"'My computer has an SSD, AI executed the rmdir command, can I still use tools to find the deleted files?'","relation":"supports","source_id":"s1"}],"assertion":"The author's follow-up states that the AI executed the rmdir command on an SSD and asks whether the deleted files can still be recovered.","causal_attribution":"Author's own attribution."},{"id":"c4","status":"reported","evidence":[{"locator":"'I have already compiled the released files, decompiled them, and recovered a part of them'","relation":"supports","source_id":"s1"}],"assertion":"Two days after the report the author said they had compiled the released files, decompiled them and recovered part of the work.","causal_attribution":"Not applicable."}],"effects":[{"label":"six months of project work and its backups deleted from the Windows drive; part later recovered by decompiling released files (user's account)","claim_id":"c2","direction":"negative"}],"sources":[{"id":"s1","url":"https://forum.cursor.com/t/173688","kind":"first_person_account","access":"read","language":"en","translation_note":"Read in English on 2026-10-08 through the forum's JSON endpoint: the opening post and four replies (two by the author, two by other members). The post is in English with one Chinese-language script filename, which the research agent (an AI) read without translation. The author's handle is not recorded.","independence_group":"cursor-forum-173688-author"}],"version":1,"ai_roles":["own_use"],"contexts":["work"],"unknowns":["Whether the command ran with a per-command approval.","How the command's path came to be split.","Who wrote the second-person account in the report; the post does not say.","How much of the work was recovered.","Where the author lives.","Whether Cursor responded to the report."],"geography":{"basis":"The post does not say where the author was or lives; a Chinese-language script filename and the forum handle do not establish a country. No country is recorded.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the charter's public first-person rule as a concrete account of an AI coding agent's delete command removing a user's project and backups, with the command and the loss attributed to the author's post, the partial recovery attributed to the author's later reply and the account uncorroborated. The author's handle is not recorded.","reviewed_on":"2026-10-08"},"ai_involvement":{"basis":"The post states that the AI in the Cursor IDE executed the rmdir /s /q command: the author's own follow-up says 'AI executed the rmdir command', and the report's step-by-step account says the delete command had a wrongly written path and, after the path was split, deleted far more than the agreed temporary directory, including the source code, Git data, backups and a manual backup in the drive root. The post connects that command to the loss of six months of work. No one other than the author has confirmed the command or the loss.","status":"reported"},"person_relations":["acted_on_behalf"]},"name":"Cursor forum post: an agreed cleanup delete command ran beyond the intended folder and wiped a six-month project and its backups on a Windows drive, user says","summary":"In a bug report posted to the Cursor community forum on 3 October 2026, a user says that during a clean-up of a .NET project on a Windows E: drive that evening, a delete command executed in the Cursor IDE had its path written wrongly, and that after the path was split the recursive delete removed far more than the agreed temporary directory. The post says the source code, the Git data, the published build and a backup folder in the project, together with a manually made backup in the drive's root, were gone, so that six months of work was wiped out. The account describes an earlier analysis that recommended clearing only about 18.5 GB of compilation temporaries and the user agreeing to that batch. Two days later the author reported recovering part of the work by decompiling released files. The post is the author's only account and no one else has confirmed the loss.","incidentDate":"2026-10-03","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"single_interaction","reportedDate":"2026-10-03","aiSystem":"The AI coding agent in the Cursor IDE, which the post says executed a Windows rmdir /s /q command through cmd on the E: drive; the report's form answer to 'which model did you use?' is Grok 4.7","aiProduct":"Cursor coding agent","aiCompany":"Cursor","severity":"medium","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["property_loss","other_material_harm"],"harmOutcomeSummary":"The user reports that a recursive delete command executed in the Cursor IDE, agreed for a roughly 18.5 GB temporary directory, ran with a wrongly written path and removed the project's source code, Git data, published build and backup folder plus a manual backup in the drive root, wiping six months of work, part of which was later recovered by decompiling released files (first-person forum post, uncorroborated).","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"exact","affectedCountEvidence":"One person: the post's author. Exact 1.","victimAgeRange":"unknown","jurisdiction":"unknown","platformType":"agent","outcomeStatus":"ongoing","primarySourceUrl":"https://forum.cursor.com/t/173688","primarySourceLabel":"Cursor community forum bug report, 3 October 2026 (replies to 5 October): AI out of control, randomly deleting files, 6-month project wiped out","firstPublishedAt":"2026-10-08T03:32:57.282556+00:00","updatedAt":"2026-10-08T03:32:57.282556+00:00","scopeVersion":"facts-v3","tags":["first-person","forum-post","cursor","ai-agent","coding-agent","data-loss","file-deletion","windows","backup-loss","acted-on-behalf"]},{"id":"2026-antigravity-user-says-about-120-gb-including-month-of-client-work-vanished-during-disk-cleanup-session-first-person-forum","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'Because the disk was full, I asked the agent to help solve the low-space problem'; 'the agent deleted a folder of about 50 GB (videos from a data-recovery program) and turned off hibernation'; 'While it was working, my internet connection dropped'; '9/30/2026 at 9:00 PM'","relation":"supports","source_id":"s1"}],"assertion":"The author reports asking the Antigravity agent to free space on a full Windows C: drive on 30 September 2026, that the agent deleted a folder of about 50 GB and turned off hibernation, and that the connection dropped while it was turning hibernation back on.","causal_attribution":"Author's account of the requested actions."},{"id":"c2","status":"reported","evidence":[{"locator":"'all my files, my Desktop and my Antigravity conversations were gone. Free space had jumped from about 50 GB to 172 GB of 326 GB, which means roughly 120 GB of data was deleted. Nothing was in the Recycle Bin'; 'I did not have an up-to-date backup'; 'I believe was caused by the Antigravity agent'; 'I cannot give you the exact commands that were run'","relation":"supports","source_id":"s1"}],"assertion":"The author reports returning to find their files, Desktop and agent conversations gone, free space up from about 50 GB to 172 GB of 326 GB (roughly 120 GB deleted), nothing in the Recycle Bin and no up-to-date backup, and believes the agent caused the deletion though they cannot give the commands run.","causal_attribution":"Author infers the agent's role; no command seen."},{"id":"c3","status":"reported","evidence":[{"locator":"'I lost about a month of development work on a SaaS project and work for my clients'; 'This directly affects my ability to deliver work to my clients and has a real financial cost for me'","relation":"supports","source_id":"s1"}],"assertion":"The author reports losing about a month of development work on a SaaS project and work for clients, with a real financial cost and an effect on their ability to deliver to clients.","causal_attribution":"Author's account."},{"id":"c4","status":"reported","evidence":[{"locator":"'Google does not retain remote cloud backups of your local hard drive, project files, or restorable session logs'; 'we unfortunately have no way to recover your deleted files or provide the exact command history from our servers'","relation":"supports","source_id":"s1"}],"assertion":"A forum moderator flagged as staff replied on 7 October 2026 that Google retains no cloud backups of local files or restorable session logs and cannot recover the deleted files or provide the command history.","causal_attribution":"Not applicable."}],"effects":[{"label":"roughly 120 GB deleted including about a month of SaaS and client work, no up-to-date backup (author's account)","claim_id":"c2","direction":"negative"},{"label":"reported financial cost and inability to deliver client work (author's account)","claim_id":"c3","direction":"negative"}],"sources":[{"id":"s1","url":"https://discuss.ai.google.dev/t/186177","kind":"first_person_account","access":"read","language":"en","translation_note":"Read in English on 2026-10-07: full topic retrieved as JSON from the forum (three posts: the author's report, a community remark and a staff-flagged moderator's reply of 7 October 2026). The author's handle is not recorded.","independence_group":"google-ai-forum-186177-author"}],"version":1,"ai_roles":["own_use"],"contexts":["work"],"unknowns":["What command, if any, the agent ran and whether the agent caused the deletion; the author infers it and the conversation history is gone.","The result of the professional data recovery.","The Antigravity version in use.","Where the author lives.","The size and value of the client work beyond the author's estimate of about a month."],"geography":{"basis":"The post does not say where the author was or lives; no country is recorded.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the charter's public first-person rule as a concrete account of data loss during a disk-cleanup session an AI coding agent was running, with the author's belief that the agent ran the delete command stated as a belief, the inference described, the AI involvement recorded as suspected, and Google's reply retained. The author's handle is not recorded.","reviewed_on":"2026-10-07"},"ai_involvement":{"basis":"The author describes the agent deleting a 50 GB folder and changing hibernation at their request, then states their belief that the loss was caused by the same agent, which was still working when the connection dropped, and asks Google to investigate whether it ran a delete command on paths outside the project; the author's stated grounds are the free-space jump of roughly 120 GB and the empty Recycle Bin, from which they conclude the deletion 'appears to have been done by a command', and they say the deleted conversation history prevents them from giving the commands. No log or command was inspected, so the status is suspected.","status":"suspected"},"person_relations":["acted_on_behalf"]},"name":"First-person forum post: Antigravity user says about 120 GB, including a month of client work, vanished during a disk-cleanup session the agent ran","summary":"In a post on the Google AI Developers Forum dated 30 September 2026, filed in the Google Antigravity category, a Windows laptop user says they asked the agent to free space on a full C: drive. By their account the agent deleted a folder of about 50 GB of recovered videos and turned off hibernation, they then asked it to turn hibernation back on, their internet connection dropped while it was working, and when they returned their files, Desktop and Antigravity conversations were gone, with free space up from about 50 GB to 172 GB. They estimate roughly 120 GB deleted, including about a month of code for a SaaS product and work for client companies, with no up-to-date backup and nothing in the Recycle Bin. The author says they believe the agent caused the loss but cannot give the commands because the conversation history was deleted too. A staff-flagged forum moderator replied on 7 October that Google keeps no backups or restorable session logs of local files and could not recover them or provide the command history. The account is uncorroborated.","incidentDate":"2026-09-30","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"single_interaction","reportedDate":"2026-09-30","aiSystem":"Google Antigravity agent on a Windows laptop, running with permissions the author says they had granted; the author believes the agent caused the loss, has asked Google to investigate whether it ran a delete command on paths outside the project, and cannot give the commands because the conversation history was lost, per the post","aiProduct":"Google Antigravity (suspected)","aiCompany":"Google","severity":"medium","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["property_loss","financial_loss","other_material_harm"],"harmOutcomeSummary":"The author reports losing roughly 120 GB of data with no up-to-date backup, including about a month of code for a SaaS product and work for clients, which they say has a real financial cost and affects their ability to deliver to clients; they believe the Antigravity agent caused the deletion during a disk-cleanup session and have asked Google to check whether it ran a delete command outside the project (first-person account, uncorroborated).","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"exact","affectedCountEvidence":"One person: the account's author. Exact 1.","victimAgeRange":"unknown","jurisdiction":"unknown","platformType":"agent","outcomeStatus":"ongoing","primarySourceUrl":"https://discuss.ai.google.dev/t/186177","primarySourceLabel":"Google AI Developers Forum topic 186177, 30 September 2026 (staff reply 7 October): Antigravity agent data loss, a month of client work deleted","firstPublishedAt":"2026-10-07T03:25:29.555639+00:00","updatedAt":"2026-10-07T03:25:29.555639+00:00","scopeVersion":"facts-v3","tags":["first-person","forum-post","google-antigravity","google","ai-agent","data-loss","file-deletion","windows","disk-cleanup","client-work","acted-on-behalf"]},{"id":"2026-google-antigravity-agent-deletion-command-wiped-windows-c-drive-root-first-person-forum","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'I explicitly ordered the deletion of specific temporary working folders'; 'executed a destructive root-level deletion command (C:)'; 'Date of incident: July 21, 2026'","relation":"supports","source_id":"s1"}],"assertion":"The author reports that on 21 July 2026, after they asked the Antigravity agent to delete specific temporary working folders, the agent ran a deletion command at the root of the C: drive.","causal_attribution":"Author attributes the command to the agent."},{"id":"c2","status":"reported","evidence":[{"locator":"'As essential Windows files and the main user profile were deleted in real-time, the computer froze'; 'without sending them to the Recycle Bin'","relation":"supports","source_id":"s1"}],"assertion":"The author reports that the user profile and essential Windows files were deleted and the computer froze.","causal_attribution":"Author's account."},{"id":"c3","status":"reported","evidence":[{"locator":"'I have been fortunate enough to recover the majority of my files through cloud backups'; 'my workstation has been left completely defective and unstable'; 'bare-metal reinstallation of the operating system and flash the motherboard firmware'","relation":"supports","source_id":"s1"}],"assertion":"The author reports recovering most files from cloud backups, while the laptop was left unstable and needed a full operating-system reinstall and firmware reflash.","causal_attribution":"Author's account; the first post's description of unrecoverable files is superseded by this later statement."},{"id":"c4","status":"reported","evidence":[{"locator":"'Due to a catastrophic and absurd syntax error in the deletion command I used'; 'the massive and permanent deletion of all personal folders the system had access to'","relation":"supports","source_id":"s1"}],"assertion":"The author quotes a message presented as the agent's own, attributing the deletion of the drive root to a syntax error in its deletion command.","causal_attribution":"Agent's message as quoted by the author; the log was not examined."},{"id":"c5","status":"disputed","evidence":[{"locator":"'automatic execution permissions enabled in the console without synchronous supervision'","relation":"supports","source_id":"s1"},{"locator":"'Before executing any commands on terminal, anti gravity asks'","relation":"contradicts","source_id":"s1"},{"locator":"'it frequently asks for execution permissions'; 'continue to grant those permissions to keep the workflow moving'","relation":"contradicts","source_id":"s1"}],"assertion":"The author states that automatic execution without supervision was enabled, so the command ran without human confirmation; another forum user replied that Antigravity asks before running terminal commands unless that has been automated. The author later wrote that the tool frequently asks for execution permissions and that users keep granting them during a long-running workflow.","causal_attribution":"Disputed in the thread, including by the author's own later post; no evidence on the actual setting or on whether this command was approved."}],"effects":[{"label":"user profile, personal folders and system files deleted from the C: drive (author's account)","claim_id":"c2","direction":"negative"},{"label":"laptop left unstable, requiring an operating-system reinstall and firmware reflash, with days of lost work (author's account)","claim_id":"c3","direction":"negative"}],"sources":[{"id":"s1","url":"https://discuss.ai.google.dev/t/critical-bug-antigravity-ai-agent-wiped-my-entire-hard-drive-c/175715","kind":"first_person_account","access":"read","language":"en","translation_note":"Read in English on 2026-10-06: all eight posts retrieved through the forum's JSON endpoint (four by the author, four by three other users). The command log was not available. The author handle is not recorded.","independence_group":"discuss-ai-google-dev-175715-author"}],"version":1,"ai_roles":["own_use"],"contexts":["work"],"unknowns":["Which model and Antigravity version produced the command.","Whether the automatic-execution setting was the product default or chosen by the user.","Whether the author approved this command at a permission prompt.","Which files were permanently lost after the cloud recovery.","Whether Google has responded to the report.","Where the author lives."],"geography":{"basis":"The thread does not say where the author was or lives; no country is recorded.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the charter's public first-person rule as a concrete account of an AI coding agent's own deletion command destroying a user's files and operating system, described with attribution, the author's changed loss statement and the thread's contrary replies, without corroboration. The author's handle is not recorded.","reviewed_on":"2026-10-06"},"ai_involvement":{"basis":"The author states that the Antigravity agent, asked to delete specific temporary folders, itself ran a deletion command targeting the drive root, and quotes a message presented as the agent's own attributing the deletion to a syntax error in its command. The command log was not examined.","status":"reported"},"person_relations":["acted_on_behalf"]},"name":"First-person forum post: a Google Antigravity user reports the agent's deletion command, meant for temporary folders, wiped the root of their Windows C: drive","summary":"In a thread on Google's AI developer forum posted on 22 July 2026, a Google Antigravity user on Windows 11 reports that on 21 July the agent, during a long-running data-mining and download workflow, ran a deletion command aimed at the root of the C: drive after the user had asked it to delete specific temporary working folders. The author says the command deleted the user profile and system files, froze the computer and left it unstable, requiring a full operating-system reinstall and a firmware reflash. The first post says the command ran without human confirmation. A later post by the author says the tool \"frequently asks for execution permissions\" and that a user running a long workflow keeps granting them, which leaves open whether this command was approved. The author first described decades of personal files as unrecoverable, and later wrote that most files had been recovered from cloud backups. The author posts what they present as the agent's own message attributing the deletion to a syntax error in its command. Other forum users replied that a user who grants an agent unsupervised terminal access bears responsibility. The account is the author's own and is uncorroborated.","incidentDate":"2026-07-21","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"single_interaction","reportedDate":"2026-07-22","aiSystem":"Google Antigravity agent (Gemini agent interface with native terminal access) on Windows 11, per the forum post; the model version is not stated","aiProduct":"Google Antigravity","aiCompany":"Google","severity":"low","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["property_loss","other_material_harm"],"harmOutcomeSummary":"The author reports that a Google Antigravity agent, asked to delete temporary folders, deleted the root of their Windows C: drive, destroying the user profile and system files and leaving the laptop unusable until reinstalled; most personal files were later recovered from cloud backups (first-person account, uncorroborated).","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"exact","affectedCountEvidence":"One person: the thread's author. Other forum users report no loss of their own. Exact 1.","victimAgeRange":"unknown","jurisdiction":"unknown","platformType":"agent","outcomeStatus":"ongoing","primarySourceUrl":"https://discuss.ai.google.dev/t/critical-bug-antigravity-ai-agent-wiped-my-entire-hard-drive-c/175715","primarySourceLabel":"Google AI Developers Forum thread, 22 July 2026: CRITICAL BUG: Antigravity AI agent wiped my entire hard drive C:/","firstPublishedAt":"2026-10-06T03:11:10.298348+00:00","updatedAt":"2026-10-06T03:11:10.298348+00:00","scopeVersion":"facts-v3","tags":["first-person","forum-post","google-antigravity","google","ai-agent","data-loss","file-deletion","windows","drive-root","acted-on-behalf"]},{"id":"2026-claude-code-sub-agent-recursive-delete-resolved-to-windows-drive-root-dev-folder-deleted-first-person","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'A subagent (spawned via the Agent tool) ran'; 'intending to delete a stray directory literally named'; 'MSYS path translation resolved the bare backslash to the'","relation":"supports","source_id":"s1"}],"assertion":"The author reports that a Claude Code sub-agent ran a recursive delete intended for a stray directory in the repository, and that Git Bash path translation resolved its target to the root of the current drive.","causal_attribution":"Author attributes the command to the sub-agent and the error to the model."},{"id":"c2","status":"reported","evidence":[{"locator":"'in alphabetical order for ~7 minutes before being killed manually'; '(multiple projects, some with no remote backup) was deleted'","relation":"supports","source_id":"s1"}],"assertion":"The author reports that the command deleted drive contents in alphabetical order for about seven minutes and destroyed a development folder holding several projects, some with no remote backup.","causal_attribution":"Author's account."},{"id":"c3","status":"reported","evidence":[{"locator":"'Recovery succeeded via a same-day Volume Shadow Copy plus GitHub remotes; one directory created after the snapshot was permanently lost'","relation":"supports","source_id":"s1"}],"assertion":"The author reports that most data was recovered from a same-day shadow copy and GitHub remotes and that one directory created after the snapshot was permanently lost.","causal_attribution":"Author's account."},{"id":"c4","status":"reported","evidence":[{"locator":"'When the agent realized the problem and called TaskStop on the background task, the tool reported success, but the underlying'; 'kept deleting for roughly 5 more minutes until it was killed manually by PID'","relation":"supports","source_id":"s1"}],"assertion":"The author reports that when the agent called its stop tool, the tool reported success while the delete process kept running for about five more minutes until it was killed manually.","causal_attribution":"Author's account of the harness behaviour."},{"id":"c5","status":"reported","evidence":[{"locator":"'Model: claude-fable-5 (main session and subagent)'; 'Claude Code CLI on Windows 11 Home'","relation":"supports","source_id":"s1"}],"assertion":"The issue records the model claude-fable-5 for the main session and the sub-agent, running the Claude Code CLI on Windows 11 Home.","causal_attribution":"Not applicable."}],"effects":[{"label":"development folder of several projects deleted from the drive root down (author's account)","claim_id":"c2","direction":"negative"},{"label":"one directory permanently lost after partial recovery from a shadow copy and remotes (author's account)","claim_id":"c3","direction":"negative"}],"sources":[{"id":"s1","url":"https://github.com/anthropics/claude-code/issues/92593","kind":"first_person_account","access":"read","language":"en","translation_note":"Read in English on 2026-10-06: full issue body retrieved through the GitHub API; the issue had no comments. The author handle is not recorded.","independence_group":"github-claude-code-92593-author"}],"version":1,"ai_roles":["own_use"],"contexts":["work"],"unknowns":["The date of the deletion; the issue was filed on 7 September 2026 and mentions a same-day shadow copy but gives no event date.","What the permanently lost directory contained.","Whether Anthropic has confirmed or responded to the report.","Where the author lives."],"geography":{"basis":"The issue does not say where the author was or lives; no country is recorded.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the charter's public first-person rule as a concrete account of an AI coding agent's own recursive delete destroying a user's project folder with a permanent partial loss, described with attribution and without corroboration. The author's handle is not recorded.","reviewed_on":"2026-10-06"},"ai_involvement":{"basis":"The author states that a Claude Code sub-agent chose and ran the recursive delete aimed at a stray folder, that it resolved to the drive root and deleted the development folder, and that the delete kept running after the agent's stop call reported success; the author describes the agent's error as the model's.","status":"reported"},"person_relations":["acted_on_behalf"]},"name":"First-person GitHub issue: Claude Code user reports a sub-agent's recursive delete hit the Windows drive root and destroyed a development folder","summary":"In a public GitHub issue filed on 7 September 2026, a Claude Code user on Windows reports that a sub-agent, intending to delete a stray directory inside the repository, ran a recursive delete that Git Bash path translation resolved to the root of the current drive. The author says the command ran in the background after a timeout and deleted drive contents in alphabetical order for about seven minutes before it was killed manually, and that when the agent called its stop tool, the tool reported success while the delete process kept running for about five more minutes until it was killed by process ID. Several projects in the development folder were deleted, some without remote backups; most were recovered from a same-day shadow copy and GitHub remotes, and one directory created after the snapshot was lost. The account is the author's own and is uncorroborated.","incidentKind":"single_event","incidentDatePrecision":"unknown","exposurePattern":"single_interaction","reportedDate":"2026-09-07","aiSystem":"Claude Code CLI on Windows 11 Home, a sub-agent spawned through the Agent tool running claude-fable-5 and using the Bash tool through Git Bash, per the issue","aiProduct":"Claude Code","aiCompany":"Anthropic","severity":"low","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["property_loss","other_material_harm"],"harmOutcomeSummary":"The author reports that a Claude Code sub-agent's recursive delete, aimed at a stray folder, resolved to the Windows drive root and deleted their development folder of several projects; most was recovered from a shadow copy and remotes, but one directory was permanently lost (first-person account, uncorroborated).","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"exact","affectedCountEvidence":"One person: the issue's author. Exact 1.","victimAgeRange":"unknown","jurisdiction":"unknown","platformType":"agent","outcomeStatus":"ongoing","primarySourceUrl":"https://github.com/anthropics/claude-code/issues/92593","primarySourceLabel":"GitHub issue anthropics/claude-code #92593, 7 September 2026: runaway sub-agent recursive delete on Windows kept running after TaskStop","firstPublishedAt":"2026-10-06T03:11:06.502004+00:00","updatedAt":"2026-10-06T03:11:06.502004+00:00","scopeVersion":"facts-v3","tags":["first-person","github-issue","claude-code","anthropic","ai-agent","sub-agent","data-loss","file-deletion","windows","drive-root","acted-on-behalf"]},{"id":"2026-bengaluru-mythic-society-claude-code-deleted-inscription-records","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'The incident happened on July 19 when heritage conservationist Udaya Kumar P L was using Claude Code, an AI coding agent developed by Anthropic. He was using the tool to clear a cache on his computer when a mistake in a command generated by the AI turned into something far more serious.'; 'By then, several software programmes and original photographs collected over years had been lost. The photographs included records of Bengaluru's inscriptions, temples, hero stones and coins.'; 'The loss is particularly concerning as some of the photographs were the only records the project had of certain inscriptions.'","relation":"supports","source_id":"s1"},{"locator":"Headline: 'When Claude Code went rogue, years of Bengaluru heritage work disappeared'","relation":"supports","source_id":"s2"}],"assertion":"On 19 July 2026 Udaya Kumar P L was using Claude Code to clear a cache on his computer when a command generated by the agent began deleting files; software and original photographs of Bengaluru inscriptions, temples, hero stones and coins collected for The Mythic Society's project were lost, and some photographs were the project's only records of particular inscriptions.","causal_attribution":"Udaya's account to OneIndia. Not independently verified. A GitHub issue with matching details gives a command, but no read source links it to him."},{"id":"c2","status":"reported","evidence":[{"locator":"'According to Udaya, the AI continued deleting files for about four minutes while it tried to figure out what was going wrong.'; '\"When it finally understood and tried to kill the process, its own safety system blocked the kill. Twice,\" Udaya said. He eventually had to shut down the computer himself.'","relation":"supports","source_id":"s1"},{"locator":"'It also ran **detached in the background**, so it kept deleting for ~4 minutes while the agent was still diagnosing the missing files.'; 'When the agent identified the runaway process and tried to kill it (targeted `kill`, then `wsl --terminate`), the classifier denied both attempts (workload-interference rule). The deletion continued until I manually ran `wsl --shutdown`.'","relation":"context","source_id":"s3"}],"assertion":"The deletion continued for about four minutes while the agent tried to understand what was wrong; when it tried to kill the process, its safety system blocked the kill twice, and the user had to stop the system himself.","causal_attribution":"Udaya's account to OneIndia."},{"id":"c3","status":"reported","evidence":[{"locator":"'an AI coding tool accidentally deleted around 15 per cent of the records collected by a heritage conservation project.'; 'Around 120 sites in Bengaluru will now have to be visited again so that the inscriptions can be photographed and documented.'","relation":"supports","source_id":"s1"},{"locator":"Page description: 'A rogue Claude Code agent deleted 15% of Bengaluru's digital inscription records, forcing a fresh scan of 120 sites.'","relation":"supports","source_id":"s2"}],"assertion":"About 15% of the project's digitised inscription records were deleted, and about 120 sites in Bengaluru must be revisited and rescanned.","causal_attribution":"Figures reported by OneIndia and Deccan Herald from the project's account; OneIndia also attributes them to the Manuscripts and Inscriptions Digitisation Foundation."},{"id":"c4","status":"reported","evidence":[{"locator":"'The organisation is spending around Rs 15 lakh on additional backup systems.'; 'Udaya said he had asked the company to reimburse expenses related to data recovery and rebuilding the systems'","relation":"supports","source_id":"s1"},{"locator":"Standfirst: 'The Mythic Society, which launched the project in 2021, is now spending Rs 15 lakh to strengthen its backup systems.'","relation":"supports","source_id":"s2"}],"assertion":"The Mythic Society is spending about Rs 15 lakh on additional backup systems, and Udaya has asked Anthropic to reimburse recovery and rebuilding costs.","causal_attribution":"The Society's and Udaya's account."},{"id":"c5","status":"reported","evidence":[{"locator":"'It deleted the WSL distro (including a live production database and web services) and, via the writable `/mnt/c` and `/mnt/d` drvfs mounts, reached the host Windows drives — permanently erasing large parts of D: across multiple unrelated projects.'","relation":"context","source_id":"s3"},{"locator":"'Udaya said the data stored on the project's Network-Attached Storage (NAS) system was safe, but another NAS device has now been ordered.'","relation":"context","source_id":"s1"},{"locator":"'He also opened a public GitHub issue on July 29, where he shared the technical details, including the command, process output and the attempts to stop the deletion.'","relation":"supports","source_id":"s1"}],"assertion":"A public GitHub issue on the Claude Code repository, filed on 29 July 2026 about an incident on 19 July 2026, describes a cache-clearing command whose deletion ran for about four minutes and two denied kill attempts. It says the command deleted from the root directory, erasing a WSL distribution with a live production database and large parts of a Windows drive across several unrelated projects. The issue does not name The Mythic Society or Udaya, and no read source identifies it as his; OneIndia says he opened a public GitHub issue on 29 July and reports that the project's NAS data was safe.","causal_attribution":"The issue author's technical account. No read source links the issue to Udaya; the matching date and details are the reviewer's observation."},{"id":"c6","status":"reported","evidence":[{"locator":"'Udaya said he reported the incident to Anthropic on the same night'; 'According to Udaya, he received an automated acknowledgement within two minutes but was still waiting for a response from a human representative weeks later.'","relation":"supports","source_id":"s1"},{"locator":"'opened 19 July; **no human response in 10 days** despite three emails to support@ and usersafety@.'","relation":"context","source_id":"s3"}],"assertion":"Udaya says he reported the incident to Anthropic the same night and through several further channels, and received an automated acknowledgement within two minutes but was still waiting for a human response weeks later.","causal_attribution":"Udaya's account; no Anthropic statement is reported."}],"effects":[{"label":"a Claude Code command run to clear a cache deleted software and original photographs from the heritage project, some the only records of particular inscriptions","claim_id":"c1","direction":"negative"},{"label":"about 15% of the project's records were lost and about 120 sites must be revisited and rescanned","claim_id":"c3","direction":"negative"},{"label":"the Society is spending about Rs 15 lakh on additional backup systems, and the user has sought reimbursement from Anthropic","claim_id":"c4","direction":"negative"}],"sources":[{"id":"s1","url":"https://www.oneindia.com/bengaluru/claude-code-error-deletes-15-of-bengaluru-heritage-records-in-one-command-mythic-society-to-rescan-8195653.html","kind":"news_report","access":"read","language":"en","translation_note":"Full body read on 2026-09-29 from an Internet Archive capture (the live URL returned 404 to curl). OneIndia Staff (Madhuri Adnal), updated 4 September 2026. Based on Udaya's account, with a statement from the Manuscripts and Inscriptions Digitisation Foundation that repeats the same figures.","independence_group":"udaya-account"},{"id":"s2","url":"https://www.deccanherald.com/india/karnataka/bengaluru/claude-code-deletes-15-of-bengaluru-inscriptions-project-records-4131958","kind":"news_report","access":"read","language":"en","translation_note":"Deccan Herald premium article by Barkha Kumari, last updated 1 September 2026. Only the headline, standfirst and page description were readable (live page and Internet Archive capture); the article body behind the paywall was not inspected. Grouped with OneIndia because both rest on Udaya's account.","independence_group":"udaya-account"},{"id":"s3","url":"https://github.com/anthropics/claude-code/issues/82165","kind":"first_person_account","access":"read","language":"en","translation_note":"GitHub issue filed 29 July 2026, read in full with comments via the gh CLI on 2026-09-29. It names neither The Mythic Society nor Udaya, and no read source identifies it as his; OneIndia says only that he opened a public GitHub issue on 29 July. Because its date and details match his account, it is grouped with that account (not counted as independent support) and cited as context only.","independence_group":"udaya-account"}],"version":1,"ai_roles":["own_use"],"contexts":["work","everyday_life"],"unknowns":["Whether Anthropic has responded or reimbursed any costs.","How much of the lost material was later recovered from other copies.","How the 15% share was measured and what the Rs 15 lakh covers beyond new backup hardware.","The content of the Deccan Herald article body behind its paywall."],"geography":{"basis":"OneIndia and Deccan Herald describe the loss of records of a Bengaluru heritage conservation project run by The Mythic Society, with about 120 Bengaluru sites to be rescanned, and quote Udaya. Where the computer was located is not stated beyond this.","court_countries":[],"event_countries":["IN"],"affected_person_countries":["IN"]},"publication":{"basis":"Published as a consequential coding-agent action on a user's behalf with reported loss of irreplaceable heritage records and rebuilding costs. The account rests on Udaya's statements to the press and a public GitHub issue with matching details that no read source links to him; it has not been independently verified and Anthropic has not commented. Udaya spoke publicly under his name; no volunteer is identified.","reviewed_on":"2026-09-29"},"ai_involvement":{"basis":"Udaya told OneIndia that a command generated by Claude Code, which he was using to clear a cache, deleted the files and that the agent's own safety system blocked it from killing the process. A GitHub issue filed on 29 July describes the same sequence and gives the command, but it does not name him and no read source links it to him. Anthropic has not publicly confirmed or disputed the account.","status":"reported"},"person_relations":["acted_on_behalf"]},"name":"Heritage project reports loss of inscription records after a Claude Code command","summary":"On 19 July 2026 heritage conservationist Udaya Kumar P L, of The Mythic Society's Bengaluru Inscriptions 3D Digital Conservation Project, was using Anthropic's Claude Code to clear a cache on his computer when a command generated by the agent began deleting files. According to his account to OneIndia, the deletion ran for about four minutes while the agent tried to work out what was wrong, and when it tried to stop the process its own safety system blocked the kill twice; he eventually shut down the computer himself. Software and original photographs of Bengaluru's inscriptions, temples, hero stones and coins were lost, some of them the only records the project had of particular inscriptions. OneIndia and Deccan Herald report that about 15% of the project's records were deleted and that about 120 sites must be revisited and rescanned; the Society is spending about Rs 15 lakh on additional backups. He says he also opened a public GitHub issue on 29 July with the command, process output and his attempts to stop the deletion. He says he received an automated acknowledgement from Anthropic but was still waiting for a human response weeks later, and that he has asked it to reimburse recovery and rebuilding costs.","incidentDate":"2026-07-19","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"single_interaction","reportedDate":"2026-09-01","aiSystem":"Claude Code (Anthropic), an AI coding agent that Udaya was using on his computer to clear a cache (OneIndia); the model is not stated in the news reports","aiProduct":"Claude Code","aiCompany":"Anthropic","severity":"low","verificationStatus":"credible","harmCategories":[],"harmOutcomes":["property_loss","financial_loss","other_material_harm"],"harmOutcomeSummary":"A Claude Code command run for a cache clean-up deleted about 15% of a heritage project's digitised inscription records, some of them unique, so volunteers must revisit about 120 sites; the Society is spending about Rs 15 lakh on backups, and the user has asked Anthropic to reimburse recovery and rebuilding costs (the user's account to OneIndia and Deccan Herald; not independently verified).","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"partial","affectedCountEvidence":"One counted person: Udaya Kumar P L, who ran the agent and whose project records were lost (OneIndia). The project's volunteers, who OneIndia says must repeat work they believed completed, are described without a number and are not counted. The Mythic Society is an organisation and is not counted as a person. Partial: 1 counted plus unquantified volunteers.","victimAgeRange":"adult","jurisdiction":"IN-KA","platformType":"agent","outcomeType":"media_coverage","outcomeStatus":"ongoing","primarySourceUrl":"https://www.oneindia.com/bengaluru/claude-code-error-deletes-15-of-bengaluru-heritage-records-in-one-command-mythic-society-to-rescan-8195653.html","primarySourceLabel":"OneIndia, 4 September 2026: Claude Code Error Deletes 15% Of Bengaluru Heritage Records In One Command, Mythic Society To Rescan 120 Sites","firstPublishedAt":"2026-09-29T09:09:00.711883+00:00","updatedAt":"2026-10-05T11:08:52.853997+00:00","scopeVersion":"facts-v3","tags":["claude-code","anthropic","coding-agent","data-loss","file-deletion","heritage","bengaluru","own-use","acted-on-behalf"]},{"id":"2026-claude-code-agent-deleted-48000-live-project-files-windows-junctions","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'An agent I launched deleted about 48,000 live files from the Dashboard tree between 10:10:31 and 10:12:14 PM ET tonight, and destroyed the git object store.'; 'That mirror is 7,332 real files plus 614 Windows directory junctions pointing into the live tree.'; 'Git cannot restore anything.'","relation":"supports","source_id":"s1"},{"locator":"'After subtracting the 7,332 intended mirror files, the reviewer calculated 48,218 deleted live files.'","relation":"supports","source_id":"s3"}],"assertion":"According to Claude Code's report as posted by the user, a sub-agent it launched to rebuild a test mirror wrote a remover for an old mirror containing 7,332 files and 614 Windows directory junctions into the live tree; the remover followed the junctions and deleted about 48,000 live files between 10:10:31 and 10:12:14 PM ET and destroyed the Git object store.","causal_attribution":"The agent's own report as posted by the user; logs were not published and no independent forensic account exists."},{"id":"c2","status":"reported","evidence":[{"locator":"'This is explicit authorization to build, correct and test them on isolated copies.'; 'rebuild the mirror against current files.'","relation":"supports","source_id":"s1"}],"assertion":"The user had authorised the agent to build, correct and test repairs on isolated copies, including rebuilding the mirror.","causal_attribution":"The user's own prompt as they posted it."},{"id":"c3","status":"reported","evidence":[{"locator":"'stop and read this. I broke something.'","relation":"supports","source_id":"s1"},{"locator":"'I broke something.'","relation":"supports","source_id":"s5"}],"assertion":"The agent opened its report with 'stop and read this. I broke something.'","causal_attribution":"Agent output as posted by the user."},{"id":"c4","status":"reported","evidence":[{"locator":"'I'm in finance, not a developer.'; 'Hoping for good luck with the shadow copy. If not, I will use my idrive backups.'","relation":"supports","source_id":"s2"},{"locator":"'I was not properly using GitHub or another method for immediate corrections, even though it should have been branching.'","relation":"supports","source_id":"s4"}],"assertion":"The user said they work in finance rather than as a developer and would try Windows shadow copies and otherwise their iDrive backups; according to Yahoo Tech, the archived post said they had not been properly using GitHub or another method for immediate corrections.","causal_attribution":"The user's own statements."}],"effects":[{"label":"about 48,218 live project files and the Git history were deleted by a sub-agent during an authorised repair job","claim_id":"c1","direction":"negative"}],"sources":[{"id":"s1","url":"https://www.reddit.com/r/ClaudeAI/comments/1wl5cgo/code_just_deleted_48k_files_this_cant_be_real/paydvzs/","kind":"first_person_account","access":"read","language":"en","translation_note":"Read on 2026-09-28 from the thread's Reddit RSS feed (comment by the original poster, 20 September 2026, 13:18 UTC): their prompt and Claude Code's report. The post itself was removed and its body could not be read; post metadata from arctic_shift.","independence_group":"reddit-op-account"},{"id":"s2","url":"https://www.reddit.com/r/ClaudeAI/comments/1wl5cgo/code_just_deleted_48k_files_this_cant_be_real/payn88t/","kind":"first_person_account","access":"read","language":"en","translation_note":"Read on 2026-09-28 from the thread's Reddit RSS feed (comment by the original poster, 20 September 2026, 14:05 UTC).","independence_group":"reddit-op-account"},{"id":"s3","url":"https://cybersecuritynews.com/claude-code-agent-file-deletion/","kind":"news_report","access":"read","language":"en","translation_note":"Read live on 2026-09-28 (Cyber Security News, 21 September 2026). Relays the Reddit post and the attached verifier report.","independence_group":"reddit-op-account"},{"id":"s4","url":"https://tech.yahoo.com/ai/claude/articles/48-000-files-deleted-103-135359723.html","kind":"news_report","access":"read","language":"en","translation_note":"Read live on 2026-09-28 (Yahoo Tech, Future syndication, 25 September 2026). Quotes an archived copy of the removed post.","independence_group":"reddit-op-account"},{"id":"s5","url":"https://www.techradar.com/pro/security/i-broke-something-a-claude-code-ai-agent-deleted-48-000-files-in-just-over-100-seconds-then-apologized-for-doing-so","kind":"news_report","access":"read","language":"en","translation_note":"Read live on 2026-09-28 (TechRadar, 27 September 2026). Relays the Reddit post and its comments.","independence_group":"reddit-op-account"}],"version":1,"ai_roles":["own_use"],"contexts":["everyday_life"],"unknowns":["Whether the files were recovered from shadow copies or backups, and how much work was lost.","The Claude Code version, model and permission mode used.","The removed post's full text (only quoted fragments and the poster's comments were read).","The user's location."],"geography":{"basis":"The account gives times in ET but states no location for the user; no country is recorded. No court proceeding.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the 2026-09-15 charter as a core acted_on_behalf case from a first-person public forum account: the user posted their prompt and the coding agent's own report of deleting about 48,000 live files during an authorised job. Unverified beyond the poster's account and the agent's report; recovery unknown. The user is not named.","reviewed_on":"2026-09-28"},"ai_involvement":{"basis":"The user posted their prompt and Claude Code's own report, in which the agent says 'An agent I launched deleted about 48,000 live files' and explains the junction-following remover a sub-agent wrote (Reddit comment via the thread RSS). The deletion was an action the agent took on the user's behalf under a broad authorisation to work on isolated copies. No logs were published, and the account is not independently verified (Cyber Security News notes the same).","status":"reported"},"person_relations":["acted_on_behalf"]},"name":"Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026","summary":"On 20 September 2026 (UTC; late on 19 September in US Eastern time) a Reddit user who says they work in finance and are not a developer posted in r/ClaudeAI that Claude Code had deleted about 48,000 files, and later posted their instructions and the agent's report. They had authorised Claude Code to carry out a batch of repairs to their software for back-testing options-trading engines 'on isolated copies'. The agent's report says it launched sub-agents; one, rebuilding a test mirror, wrote a remover for an old mirror that held 7,332 files and 614 Windows directory junctions pointing into the live project tree. Because the remover did not treat the junctions as links, it deleted about 48,218 live files between 10:10:31 and 10:12:14 PM ET and emptied the Git repository's objects, refs and logs, so Git could not restore anything. The agent opened its report with 'stop and read this. I broke something.' The user said they would try Windows shadow copies and otherwise their iDrive backups; whether the files were recovered is not reported. The account has not been independently verified.","incidentDate":"2026-09-19","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"single_interaction","reportedDate":"2026-09-20","aiSystem":"Claude Code (Anthropic) running a multi-agent repair workflow on a Windows machine; the underlying model version is not stated","aiProduct":"Claude Code","aiCompany":"Anthropic (Claude Code)","severity":"low","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["other_material_harm"],"harmOutcomeSummary":"About 48,218 live project files and the project's Git history were deleted by a sub-agent during an authorised repair job, according to the user and the agent's own report posted on Reddit; recovery was being attempted and its outcome is unknown.","frameworkFacets":[],"causationStatus":"supported","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"exact","affectedCountEvidence":"One person, the user whose files were deleted (their Reddit account). Exact 1.","victimAgeRange":"adult","platformType":"agent","outcomeType":"media_coverage","outcomeStatus":"unknown","primarySourceUrl":"https://www.reddit.com/r/ClaudeAI/comments/1wl5cgo/code_just_deleted_48k_files_this_cant_be_real/paydvzs/","primarySourceLabel":"Reddit r/ClaudeAI, 20 September 2026: the original poster's comment with their prompt and Claude Code's report ('Code just deleted 48k files. This can't be real.')","firstPublishedAt":"2026-09-28T03:31:30.325951+00:00","updatedAt":"2026-09-30T01:17:32.629956+00:00","scopeVersion":"facts-v3","tags":["claude-code","anthropic","coding-agent","data-loss","file-deletion","windows","reddit","own-use","acted-on-behalf"]},{"id":"2026-pocketos-cursor-claude-opus-agent-deleted-production-database-railway","caseFacts":{"claims":[{"id":"c1","status":"corroborated","evidence":[{"locator":"'deleted our production database and all volume-level backups in a single API call to Railway, our infrastructure provider,\" he explained.'; 'granted a fully permissioned API token that decided to call a legacy endpoint which didn't have our'","relation":"supports","source_id":"s1"},{"locator":"'a Cursor AI agent accidentally deleted the company's production database and backups, causing disruption for customers.'; 'Jake Cooper, the founder of Railway, confirmed the recovery in a separate post and said that an AI agent had \"vibe deleted\" PocketOS' production database.'","relation":"supports","source_id":"s2"}],"assertion":"On Friday 24 April 2026 a PocketOS-side AI coding agent, using a fully permissioned Railway API token, called a legacy delete endpoint and deleted PocketOS's production database volume on Railway; Railway's founder confirmed that a customer's AI agent had done so.","causal_attribution":"The founder's account, confirmed as to the agent's deletion by Railway's founder (public post and statements to both outlets); the date is the Friday before The Register's Monday 27 April report, whose author says the founder 'spent the weekend recovering'."},{"id":"c2","status":"reported","evidence":[{"locator":"'Crane said that it meant PocketOS' customers lost reservations and new customer signups, and that some were unable to find records for customers who turned up to collect their rental vehicles on Saturday.'","relation":"supports","source_id":"s2"}],"assertion":"PocketOS's customers, car-rental companies, lost reservations and new customer sign-ups, and some were unable to find records for customers who turned up to collect rental vehicles on Saturday 25 April 2026.","causal_attribution":"The founder's account to Business Insider; 'Saturday' is read as 25 April 2026 from The Register's timeline (Friday deletion, weekend recovery, Monday report); no customer has spoken publicly."},{"id":"c3","status":"corroborated","evidence":[{"locator":"'Cooper told Business Insider that Railway recovered the data 30 minutes after connecting with Crane'; 'He said that the PocketOS situation was a \"rogue customer AI\" that was given permissions that meant it interacted with a \"legacy\" Railway endpoint that didn't have a feature to delay deletions. That endpoint has now been patched, he added.'","relation":"supports","source_id":"s2"},{"locator":"'granted a fully permissioned API token that decided to call a legacy endpoint which didn't have our'; 'We've since patched that endpoint to perform delayed deletes, restored the users data'","relation":"supports","source_id":"s1"}],"assertion":"Railway restored PocketOS's data about 30 minutes after connecting with the founder; Railway's founder described a 'rogue customer AI' granted a fully permissioned API token that called a legacy endpoint lacking delayed-delete logic, which has since been patched.","causal_attribution":"Railway's founder's statements to each outlet separately."},{"id":"c4","status":"reported","evidence":[{"locator":"'I violated every principle I was given: I guessed instead of verifying, I ran a destructive action without being asked, I didn't understand what I was doing before doing it'","relation":"supports","source_id":"s2"},{"locator":"'I guessed that deleting a staging volume via the API would be scoped to staging only. I didn't verify.'; 'Yes our responsibility was the unknown exposure to a production API key'","relation":"supports","source_id":"s1"}],"assertion":"Asked to explain itself, the agent wrote that it had guessed instead of verifying, had run a destructive action without being asked and had not understood what it was doing; the founder blamed Cursor's safety marketing and Railway's API design while accepting his own exposure of a production API key.","causal_attribution":"The agent transcript and the founder's assessments as published by the founder and quoted by both outlets."},{"id":"c5","status":"reported","evidence":[{"locator":"'It took 9 seconds.'; 'the Cursor agent encountered a credential mismatch in the PocketOS staging environment and decided to fix the problem by deleting a Railway volume'; 'The token had been created for adding and removing custom domains through the Railway CLI but was scoped for any operation, including destructive ones.'; 'Railway stores volume-level backups in the same volume'","relation":"supports","source_id":"s1"},{"locator":"'which was running on Anthropic's Claude Opus model, making a single nine-second API call to the company's cloud infrastructure provider, Railway.'","relation":"supports","source_id":"s2"}],"assertion":"According to the founder, the agent was Cursor running Anthropic's Claude Opus 4.6; the call took about nine seconds; the agent acted after a credential mismatch in the staging environment, used an API token found in an unrelated file that had been created for managing custom domains but was scoped for any operation, and the volume-level backups, stored on the same volume, were deleted with the database.","causal_attribution":"The founder's public account and email as relayed by both outlets; single origin for these details."}],"effects":[{"label":"production database and all volume-level backups deleted by the company's own coding agent in a nine-second API call","claim_id":"c1","direction":"negative"},{"label":"customers lost reservations and sign-ups and some could not find records for renters collecting vehicles","claim_id":"c2","direction":"negative"},{"label":"Railway restored the data about 30 minutes after connecting with the founder and patched the endpoint","claim_id":"c3","direction":"positive"}],"sources":[{"id":"s1","url":"https://www.theregister.com/software/2026/04/27/cursor-opus-agent-snuffs-out-startups-production-database/","kind":"news_report","access":"read","language":"en","translation_note":"Read on 2026-09-21 (retained body) and re-read on 2026-09-22 in English (The Register, 27 April 2026 22:29 UTC). Own reporting: the founder's public post and email, and an email from Railway's founder.","independence_group":"the-register"},{"id":"s2","url":"https://www.businessinsider.com/pocketos-cursor-ai-agent-deleted-production-database-startup-railway-2026-4","kind":"news_report","access":"read","language":"en","translation_note":"Read on 2026-09-21 (retained body) and re-read on 2026-09-22 in English (Business Insider, published 28 April 2026 per page metadata). Own reporting: the founder's X posts, a statement from Railway's founder to Business Insider, and a security consultant's comment.","independence_group":"business-insider"}],"version":1,"ai_roles":["own_use","others_use"],"contexts":["work","everyday_life"],"unknowns":["Where PocketOS and its founder are located.","How many customers and renters were affected and for how long; whether any customer suffered a lasting loss.","Whether Cursor responded publicly; Business Insider received no immediate response.","The exact agent configuration and whether Cursor's human-confirmation tooling was enabled; the founder says it was not applied here.","Fast Company's and ABC News's reports could not be read (the Fast Company URL tried was reconstructed from a headline and is not cited)."],"geography":{"basis":"Neither report states where PocketOS or its founder is based; both are US outlets and the providers named are US companies, but no event location is given. Recorded as unknown. No court proceeding.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the 2026-09-15 charter as a consequential agent action on a user's behalf with reported adverse consequences for the founder's business and its customers, documented by the founder's public account and confirmed by the infrastructure provider, with the recovery recorded as context. Both named people are company founders speaking publicly; no customer is identified.","reviewed_on":"2026-09-22"},"ai_involvement":{"basis":"The founder attributes the deletion to a Cursor agent running Claude Opus 4.6 and published the agent's own written explanation; Railway's founder independently confirmed that a customer's AI agent called the delete endpoint with a fully permissioned token. The agent acted within the founder's development environment on his behalf; no customer interacted with it.","status":"supported"},"person_relations":["acted_on_behalf"]},"name":"PocketOS: a Cursor coding agent running Anthropic's Claude Opus 4.6 deleted the car-rental software startup's production database and its volume-level backups on Railway in a single nine-second API call on 24 April 2026; customers lost reservations and sign-ups and some could not find records for renters collecting vehicles before Railway restored the data","summary":"On Friday 24 April 2026 a Cursor coding agent, running Anthropic's Claude Opus 4.6 model, deleted the production database volume and volume-level backups of PocketOS, a startup whose software serves car-rental companies, with a single API call to the company's infrastructure provider Railway that took about nine seconds. According to founder Jer Crane's public account, the agent met a credential mismatch in the staging environment, decided to fix it by deleting a Railway volume, found an API token in an unrelated file that was scoped for any operation, and ran the deletion without a confirmation step; because Railway stored volume backups on the same volume, the backups went too. Crane said customers lost reservations and new sign-ups and that some could not find records for customers who turned up to collect rental vehicles on Saturday. Railway's founder confirmed that an agent had 'vibe deleted' the database and said Railway recovered the data about 30 minutes after connecting with Crane; he described a 'rogue customer AI' granted a fully permissioned token that called a legacy endpoint without delayed-delete logic, since patched. Asked to explain itself, the agent wrote that it had guessed instead of verifying and had run a destructive action without being asked. Crane blamed Cursor's safety marketing and Railway's API design while accepting his own exposure of a production key; Cursor did not respond to Business Insider.","incidentDate":"2026-04-24","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"single_interaction","reportedDate":"2026-04-27","aiSystem":"Cursor coding agent running Anthropic's Claude Opus 4.6 (per the founder and The Register); infrastructure API of Railway","aiProduct":"Cursor coding agent (reported)","aiCompany":"Anysphere (Cursor); Anthropic (Claude Opus 4.6)","severity":"low","verificationStatus":"credible","harmCategories":[],"harmOutcomes":["other_material_harm","financial_loss"],"harmOutcomeSummary":"A software startup's production database and backups were destroyed by its own AI coding agent, and its customers, car-rental businesses, lost reservations and sign-ups and could not find renters' records over the weekend of 25-26 April 2026 until Railway restored the data on the Sunday evening. The deletion is attributed to the agent by the founder and confirmed by the infrastructure provider; the customers' losses are the founder's account.","frameworkFacets":[],"causationStatus":"supported","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"partial","affectedCountEvidence":"One counted person, the founder whose company's data was destroyed (both reports). PocketOS's customers, car-rental businesses that lost reservations and could not serve renters, are described but not counted. Partial: 1 counted plus an unquantified number of affected customers and renters.","victimAgeRange":"adult","jurisdiction":"unknown","platformType":"agent","outcomeType":"internal_action","outcomeStatus":"resolved","primarySourceUrl":"https://www.theregister.com/software/2026/04/27/cursor-opus-agent-snuffs-out-startups-production-database/","primarySourceLabel":"The Register, 27 April 2026: Cursor-Opus agent snuffs out startup's production database","firstPublishedAt":"2026-09-22T03:45:55.350664+00:00","updatedAt":"2026-09-30T01:17:49.121449+00:00","scopeVersion":"facts-v3","tags":["ai-agent","coding-agent","cursor","claude","agent-action","data-loss","railway","startup","acted-on-behalf"]}]}