{"meta":{"exportedAt":"2026-10-10T08:04:15.782Z","formatVersion":2,"selection":{"q":"skip-permissions","system":"","harm":"","context":"","country":"","role":"","relation":"","evidence":"","year":"2026","response":"","severity":"","verification":"","view":"incidents","sort":"added"},"totalIncidents":1,"coverage":{"cases":1,"countries":0,"languages":1,"unknownLocation":1,"locationPending":0,"unknownLanguage":0,"unknownDate":0,"lawsuits":0,"regulatory":0,"minors":0,"coreRelations":1,"contextualRelations":0,"mixedRelations":0,"unknownRelations":0,"relationPending":0,"relationUnknown":0},"countingNote":"Distinct public cases in this selection. People counts apply within individual cases only; cross-case person overlap has not been resolved. No population incidence estimate.","affectedCountNote":"Interpret person counts with affectedCountStatus and the reported effects. Unquantified zeros are placeholders, not a measured zero.","source":"AI incidents","publisher":"NOPE","url":"https://nope.net/incidents","license":"CC BY 4.0"},"incidents":[{"id":"2026-claude-code-opus-5-5-hands-free-skip-permissions-session-deleted-developer-windows-c-drive-first-person","caseFacts":{"claims":[{"id":"c1","status":"reported","evidence":[{"locator":"'Opus 5.5 just deleted my entire fucking C drive'; 'Thank GOD I have daily backups running to my Synology NAS'","relation":"supports","source_id":"s1"},{"locator":"'A developer says Anthropic’s most powerful model wiped his computer’s entire C: drive while working on its own, and only his nightly backups saved him'","relation":"context","source_id":"s4"}],"assertion":"The developer says Claude Code running Opus 5.5 deleted the entire C drive of the developer's machine, and that daily backups to a Synology NAS saved the data.","causal_attribution":"The developer's own account, with a screenshot attached to the first post showing an analysis of unstated authorship that quotes the command; MadRobot says the account \"hasn’t been independently checked\"."},{"id":"c2","status":"reported","evidence":[{"locator":"'I have many multi-hour long sessions running at any given point in time (deliberately) on a hands free basis'; 'I've run sessions on this machine with the --dangerously-skip-permissions tag since Opus 4.6 (probably sooner tbh) without this kind of issue surfacing'; 'For a simple powershell syntax mangling issue to cause such a catastrophic problem (on opus 5.5 nonetheless) is wild to me'","relation":"supports","source_id":"s2"},{"locator":"image attached to the post: 'It was one of your own Claude Code sessions'; 'It was running in bypass-permissions mode'; 'The quoting is wrong for Windows PowerShell 5.1'; 'a bare \\ means the root of drive C:'","relation":"supports","source_id":"s1"}],"assertion":"The developer says the sessions run for hours unattended with the --dangerously-skip-permissions flag, as they had since Opus 4.6 without such an issue, and attributes the deletion to a PowerShell syntax mangling issue, and a screenshot attached to the first post quotes a folder-removal command whose quoting Windows PowerShell 5.1 resolved to the root of drive C:.","causal_attribution":"The developer's own explanation of the session setup and of the cause; the screenshot attached to the first post quotes the command and explains the quoting error, and its author is not stated."},{"id":"c3","status":"reported","evidence":[{"locator":"'I have built the appropriate deterministic safeguards to prevent this from happening again & have been able to recover 98% of my data'; 'It's nobodies fault but I'm own'","relation":"supports","source_id":"s2"}],"assertion":"The developer says 98% of the data has been recovered and that deterministic safeguards have been built, and accepts the fault as the user's own.","causal_attribution":"The developer's own account of the recovery."},{"id":"c4","status":"documented","evidence":[{"locator":"'This is the reason why we recommend (and default to) auto mode for permissions. It almost certainly would have caught this, is there a reason you aren’t using it?'","relation":"supports","source_id":"s3"},{"locator":"'Boris Cherny, who leads Claude Code at Anthropic, replied that this is exactly why the company recommends its newer permissions setting'","relation":"context","source_id":"s4"}],"assertion":"Anthropic's head of Claude Code replied publicly that the company recommends and defaults to auto mode for permissions, which \"almost certainly would have caught this\", and asked why the developer was not using it.","causal_attribution":"The reply is the cited record itself. It is a vendor response and does not confirm or dispute the deletion; Anthropic made no formal statement."},{"id":"c5","status":"reported","evidence":[{"locator":"image attached to the post: 'It wasn't admin. That's why Program Files, Windows and the other accounts survived'; 'A safety check had already blocked an earlier version of the cleanup at 3:52 PM. The session then retried it as a separate cmd /c rmdir command that the check didn't catch'","relation":"supports","source_id":"s1"}],"assertion":"The screenshot attached to the developer's first post says the session was not running as administrator, so Program Files, Windows and other accounts' files survived, and that a safety check had blocked an earlier version of the cleanup before the session retried it as a separate command.","causal_attribution":"Analysis of unstated authorship posted by the developer; the logs it drew on were not published."}],"effects":[{"label":"Coding agent's mis-quoted folder-removal command ran against the root of the Windows C: drive during an unattended session; 98% recovered from backups (developer's account)","claim_id":"c1","direction":"negative"}],"sources":[{"id":"s1","url":"https://x.com/PerceptualPeak/status/2107621483392446572","kind":"social_media_post","access":"read","language":"en","translation_note":"Read in English on 2026-10-09 through the fxtwitter API copy of the post (full text, 1,028,548 views and 855 replies at fetch time). Replies in the thread other than those cited were not retrieved. Re-read from the saved copy on 2026-10-10. The attached image (a screenshot of text, media.photos[0] in the fxtwitter copy) was read; its command path, which carries the developer's Windows account name and a project folder, is not reproduced.","independence_group":"x-developer-thread"},{"id":"s2","url":"https://x.com/PerceptualPeak/status/2107720127181738135","kind":"social_media_post","access":"read","language":"en","translation_note":"Read in English on 2026-10-09 and re-read from the saved copy on 2026-10-10 through the fxtwitter API copy (full text). The developer's reply to Boris Cherny.","independence_group":"x-developer-thread"},{"id":"s3","url":"https://x.com/bcherny/status/2107695244238324001","kind":"social_media_post","access":"read","language":"en","translation_note":"Read in English on 2026-10-09 and re-read from the saved copy on 2026-10-10 through the fxtwitter API copy (full text). Reply by Anthropic's head of Claude Code to the developer's first post.","independence_group":"anthropic-claude-code-lead"},{"id":"s4","url":"https://madrobot.blog/2026/10/07/claude-opus-5-5-deleted-c-drive-claude-code-auto-mode-boris-cherny/","kind":"news_blog","access":"read","language":"en","translation_note":"Read in English on 2026-10-09 and re-read from the saved copy on 2026-10-10 (direct fetch, 200). The blog relays the X thread and the Cherny reply and adds Anthropic's published auto-mode figures; it reports no independent checking of the account.","independence_group":"x-developer-thread"}],"version":1,"ai_roles":["own_use"],"contexts":["work","everyday_life"],"unknowns":["The developer's country.","The author of the analysis in the attached screenshot and the logs it drew on; which files were deleted, since the screenshot says Program Files, Windows and other accounts survived while the posts say the entire C drive.","The Claude Code version and the 2% of data not recovered.","Whether Anthropic investigated the session beyond the public reply.","The developer's local date at the time of the deletion; the first post was made at 23:58 UTC on 6 October 2026."],"geography":{"basis":"No source states where the developer is; the X profile and the blog give no location. No court proceedings.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the public-forum rule as a concrete first-person account of a coding agent deleting the user's system drive during an unattended session, with the deletion, the session setup and the recovery attributed to the developer and the vendor's public reply recorded. The source handle appears only in the source URLs; the developer is not named in the record. The AI contribution rests on the developer's statement that the agent's mangled PowerShell command deleted the drive and on the screenshot the developer attached, which quotes the command; the author of that analysis is not stated.","reviewed_on":"2026-10-10"},"ai_involvement":{"basis":"The developer states that Claude Code running Opus 5.5 deleted the entire C drive during a hands-free session started with the --dangerously-skip-permissions flag, and attributes the deletion to a mangled PowerShell command the agent ran; a screenshot the developer attached quotes the rmdir command and attributes the drive-root deletion to a Windows PowerShell 5.1 quoting error (author of the analysis not stated); the agent's own command is the described action and the drive deletion is its described consequence. Anthropic's head of Claude Code replied by recommending auto mode, which the reply said would almost certainly have caught the command; the reply responds to the account without confirming or disputing the deletion. The connection between the agent's action and the loss rests on the developer's own statements, and the logs behind the attached analysis have not been published.","status":"reported"},"person_relations":["acted_on_behalf"]},"name":"Developer says a hands-free Claude Code session on Opus 5.5 deleted the entire Windows C: drive; 98% recovered from daily backups (first-person, X)","summary":"In X posts of 6 and 7 October 2026, a developer writes that Claude Code running Anthropic's Opus 5.5 model \"just deleted my entire fucking C drive\" during a hands-free session, and that daily backups to a NAS saved the data. In a follow-up the developer says the sessions run for hours unattended with the --dangerously-skip-permissions flag, as they had since Opus 4.6 without such an issue, attributes the deletion to \"a simple powershell syntax mangling issue\", says 98% of the data has been recovered and that deterministic safeguards have since been built, and accepts the fault as the user's own while arguing that the harness should prevent such a command natively. The head of Claude Code at Anthropic replied that the company recommends and defaults to auto mode for permissions, which \"almost certainly would have caught this\"; the developer answered that auto mode had felt like babysitting for long unattended sessions. The account is the developer's own. The first post carries a screenshot of a text analysis addressed to the developer, whose author is not stated; it says the session was a Claude Code session in bypass-permissions mode that tried to remove two leftover git worktree folders, quotes the removal command, explains that Windows PowerShell 5.1 read its quoting so that the path became the root of drive C:, and says the session was not running as administrator, so Program Files, Windows and other accounts' files survived. MadRobot wrote that the developer had not shared a command log or screenshots showing what ran.","incidentDate":"2026-10-06","incidentKind":"single_event","incidentDatePrecision":"day","exposurePattern":"single_interaction","reportedDate":"2026-10-06","aiSystem":"Claude Code (Anthropic's coding agent) running the Claude Opus 5.5 model in a multi-hour hands-free session started with the --dangerously-skip-permissions flag on a Windows machine, where the developer says a mangled PowerShell command deleted the C: drive, per the developer's posts and the screenshot attached to the first post","aiProduct":"Claude Code (reported)","severity":"low","verificationStatus":"unverified","harmCategories":[],"harmOutcomes":["property_loss","other_material_harm"],"harmOutcomeSummary":"The developer says the agent deleted the entire C: drive of a Windows machine during an unattended session; the developer reports recovering 98% of the data from daily backups, with the remaining loss and the recovery effort unquantified; the screenshot the developer attached says the session was not running as administrator and that Program Files, Windows and other accounts survived (first-person account, uncorroborated).","frameworkFacets":[],"causationStatus":"alleged","participantUsersAffectedMin":1,"otherPeopleHarmedMin":0,"affectedCountStatus":"exact","affectedCountEvidence":"One person counted: the developer who ran the session and whose drive was deleted. The thread's view count is an audience figure and is not counted.","victimAgeRange":"unknown","platformType":"agent","outcomeStatus":"resolved","primarySourceUrl":"https://x.com/PerceptualPeak/status/2107621483392446572","primarySourceLabel":"Developer's X post, 6 October 2026: \"Opus 5.5 just deleted my entire ... C drive\"","firstPublishedAt":"2026-10-10T03:12:02.186995+00:00","updatedAt":"2026-10-10T03:12:02.186995+00:00","scopeVersion":"facts-v3","tags":["first-person","x-twitter","coding-agent","data-loss","windows","skip-permissions","claude-code","backups"]}]}