OpenAI DevDay 2026: Dots Agents, GPT-6.1 Sol, $500 Plan
On Sunday, September 20, a developer posted to Reddit that Claude Code had deleted 48,218 live files from their project and wiped the Git object store behind it in 103 seconds flat. CyberSecurityNews picked the report up the next day. By September 25 and 26, TechRadar, Yahoo, and a string of other outlets were running it too, and itâs still spreading as we publish this. Thereâs a real, useful, verifiable story buried in here about how Claude Codeâs permission system works and where it doesnât protect you. Thereâs also a claim nobody outside one Reddit thread has independently confirmed. Both things are true at once, and conflating them does readers a disservice â so weâre going to keep them separate.
Weâve spent the last week on three straight posts about OpenAI agents breaching government websites, hacking Australiaâs Medicare portal, and generally wandering past boundaries nobody drew for them. This oneâs different in kind. Itâs not an agent scheming around a rate limit â itâs an agent doing exactly the destructive thing it was told to do, just against the wrong 48,218 files. Thatâs a tool-configuration failure mode, and itâs the kind our readers can actually do something about before it happens to them.
Quick Summary: What Was Reported
Detail Info Reported Reddit post, September 20, 2026; first tech coverage by CyberSecurityNews, September 21 Claimed damage 48,218 live project files deleted; .git/objects,refs, andlogsemptiedWindow 10:10:31 p.m. to 10:12:14 p.m. ET â 103 seconds Trigger task A mirror-rebuild job labeled task â#873â Root mechanism A Python cleanup script followed 614 Windows directory junctions back into the live project tree instead of stopping at the temp mirror copy Verification status Unconfirmed. The original post and its attached verifier report were deleted before any outside forensic review; an archived copy is the only record Related, separate evidence GitHub issue #92589 on anthropics/claude-code documents a different userâs Claude Code deleting files against instructions, filed September 7 and closed for lack of reproduction steps Bottom line: Treat the 48,218 number as unverified. Treat the mechanism â an agent given broad file-deletion authority failing to distinguish a temp copy from the live tree â as entirely plausible and worth guarding against regardless of whether this specific account checks out.
Hereâs the sequence as described in the original post and repeated across the outlets that covered it. The developer had Claude Code working on task #873: rebuild a mirror of the project. The agent found that its build_mirror.py script couldnât refresh an existing mirror in place, so â on its own initiative â it wrote a Python cleanup script to clear out an older mirror copy sitting in a temporary directory first.
That old mirror held 7,332 ordinary files. It also held 614 Windows directory junctions, which are filesystem links that point somewhere else entirely â in this case, back into the live project tree. According to the reporting, the cleanup script called os.walk() with a junction guard that only checked the top level of each linked folder. Anything nested underneath a junction walked straight through as if it were a normal, disposable directory. TechRadarâs account adds that os.path.islink() â the Python check meant to catch exactly this â simply returns False for a Windows junction, so the guard never fired at all.
The script ran for 103 seconds, between 10:10:31 and 10:12:14 p.m. ET, and deleted 55,550 files total. Subtract the 7,332 files it was actually supposed to clear, and you get 48,218 live project files gone â plus, critically, the projectâs .git/objects, refs, and logs directories, which is what turns ârecoverable with git checkoutâ into âgone.â The index file reportedly survived and still listed thousands of tracked paths, but with the underlying blobs deleted, there was nothing left for Git to check those paths out from. Per TechRadar, the agent flagged its own mistake mid-run â âCraig â stop and read this. I broke somethingâ â which is either a small mercy or darkly funny, depending on how much youâd already lost by the time you read it.
The original Reddit post drew thousands of upvotes and over a thousand comments before its authorâs account was deleted, taking the post and its attached âverifier reportâ down with it. Whatâs left is an archived copy â not a forensic log, not a statement from Anthropic, not an independent researcher who reproduced the failure. CyberSecurityNews said as much in its own writeup, calling it âa user-reported incident with no independently verified attribution to a specific Claude Code defect.â
That doesnât make it fake. Deleted Reddit accounts and self-serving PR reasons for staying quiet are common enough that âthe evidence disappearedâ isnât itself suspicious. But it does mean every specific number in that Quick Summary table â 48,218, 614, 103 seconds â traces back to one unverified source, and weâd be misleading you to report it as confirmed fact. What is independently documented is the failure pattern. GitHub issue #92589, filed against Anthropicâs own repository on September 7 â two weeks before the Reddit post existed â has a different user reporting that Claude Code is âgetting worst and worst unwanted deletion, not following any instruction.â Anthropicâs team closed it labeled needs-repro, without an engineer confirming a root cause. Different incident, different user, same shape: an agent deleting files nobody asked it to touch, and a company that couldnât (or didnât) reproduce it before closing the ticket.
Put those two data points side by side and the honest read isnât âconfirmed, 48,218 files, case closed.â Itâs âa specific viral number we canât verify, sitting on top of a general failure mode that Anthropicâs own bug tracker shows is real and, as of this closed issue, unresolved.â
Whether or not this exact incident happened as described, the configuration mistakes it illustrates are real and documented in Anthropicâs own materials. Four things actually reduce your exposure:
bypassPermissions outside a disposable environment. Anthropicâs own documentation is direct about this: bypassPermissions mode âdisables permission prompts and safety checks so tool calls execute immediately,â and the docs carry an explicit warning to âonly use this mode in isolated environments like containers, VMs, or dev containers without internet access, where Claude Code cannot damage your host system.â A live project tree on a developerâs own machine is precisely the environment that warning is about..git folder. A local-only repo does not./rewind. A Python cleanup script executed via Bash, exactly like the one described in this report, falls entirely outside that safety net.None of that requires trusting the 48,218 figure. It requires reading Anthropicâs own permission and checkpoint docs, which describe these exact gaps regardless of what happened in one Reddit thread.
Weâve written before about how auto mode became Claude Codeâs default permission setting for Pro, Max, and Team accounts in August â a classifier reviewing actions instead of a human clicking âyesâ on every prompt. Auto mode is a meaningful step up from no oversight at all, and Anthropicâs own testing showed it catching far more injected dangerous commands than humans did. But this incident, if it happened as described, wasnât a case of a classifier missing something subtle. It was a case of a script executed inside a permission mode built to skip review entirely, running headfirst into a filesystem quirk â Windows junctions defeating a Python link check â that no classifier gets a vote on, because bypassPermissions means nothing gets reviewed in the first place.
Thatâs also the same distinction we made when Claude Code shipped self-hosted execution environments back in August: moving where an agent runs doesnât change what itâs permitted to do once itâs running. Self-hosting relocates the blast radius. bypassPermissions widens it. Neither one is the same lever as âdoes this agent have the ability to walk its own cleanup script into your live project tree without anyone signing off.â That lever is permission mode, full stop, and itâs the one this story is actually about.
Every AI coding tool with filesystem write access carries some version of this risk â itâs not unique to Claude Code, and itâs not new in kind, either: destructive scripts following symlinks into places they shouldnât have been able to reach is a decades-old category of bug that predates agentic AI by a long way. Whatâs new is the speed. A human running a bad cleanup script notices somethingâs wrong after a few seconds of unexpected disk activity and hits Ctrl-C. An agent given bypassPermissions and a task doesnât pause to notice â it runs to completion, and completion here took 103 seconds to touch 55,550 files. If our guide comparing Cursor, Claude Code, and Copilot is on your reading list because youâre picking an agentic coding tool right now, permission-mode defaults and what each vendorâs checkpoint system actually covers deserve the same scrutiny youâd give pricing and model quality.
We think the 48,218 number should be reported the way weâre reporting it here â sourced to a single, now-unverifiable Reddit account, worth taking seriously, not worth repeating as settled fact. Outlets that ran headlines stating it as established loss did their readers a disservice, even if the underlying mechanism turns out to be exactly right. âAllegedlyâ is doing real work in a story like this, and it shouldnât get dropped by the third or fourth outlet down the syndication chain.
What we donât think is debatable: bypassPermissions mode existing, doing exactly what Anthropicâs docs say it does, and checkpointing not covering Bash-driven deletions or symlinked paths. Those are documented facts about the product, verifiable independent of a single Reddit post, and theyâre the actual, actionable takeaway here whether or not this specific developer lost exactly 48,218 files on exactly the night described. If youâre running Claude Code with broad file-system access outside a disposable container, this is your reminder to check which permission mode your sessions actually start in â and to make sure your Git history lives somewhere rm canât reach it.
Thatâs what a since-deleted Reddit post claimed, corroborated only by an archived copy and an attached âverifier reportâ that was also removed before any independent forensic investigation could confirm the numbers. CyberSecurityNews, which covered the claim the day after it appeared, described it as âa user-reported incident with no independently verified attribution to a specific Claude Code defect.â Treat the specific figure as unverified; treat the underlying failure mode as plausible and worth guarding against.
A Python cleanup script Claude Code wrote to clear an old mirror directory used a link-detection check that didnât recognize Windows directory junctions. The mirror contained 614 junctions pointing back into the live project tree, and the script walked through them and deleted real files instead of stopping at the disposable copy.
No, though they describe the same failure pattern. Issue #92589 was filed by a different user on September 7, nearly two weeks before the Reddit post appeared, reporting that Claude Code was deleting files without instruction. Anthropicâs team closed it as unreproduced. The two reports arenât the same incident, but together they suggest unwanted deletion isnât a one-off.
bypassPermissions is a Claude Code permission mode that skips approval prompts so tool calls, including file deletions, execute immediately. Anthropicâs documentation warns it should only be used inside isolated containers or VMs, not on a machine holding your live project files. The Reddit report doesnât confirm which permission mode was active, but running any bulk deletion task outside an isolated environment carries this exact risk regardless.
Almost certainly not, per Anthropicâs own documentation. Checkpointing doesnât track changes made through Bash commands â only edits made with Claudeâs built-in file-editing tools â and a Python script run via Bash falls outside that coverage entirely. Checkpointing also explicitly skips restoring symlinked and hard-linked paths, which is the same category of link (Windows junctions) implicated in this report.
Keep bulk-deletion and cleanup tasks inside a disposable container or VM rather than running them with broad permissions against your live working directory. Commit and push to a remote before any large file operation, since a wiped local .git folder isnât recoverable from the working copy alone. And donât assume Claude Codeâs checkpoint system covers Bash-driven changes or linked files â it doesnât, by design.
Last updated: September 28, 2026. Sources: CyberSecurityNews â Claude Code Agent Allegedly Deletes 48,000 Files in 103 Seconds ¡ TechRadar â âI broke somethingâ: A Claude Code AI agent deleted 48,000 files ¡ GitHub â anthropics/claude-code issue #92589 ¡ Anthropic â Choose a permission mode ¡ Anthropic â Checkpointing.
Related reading: Claude Code Just Stopped Asking Permission ¡ Claude Code Self-Hosted: The Fix for Rogue Agents? ¡ OpenAI Agents Breached SEC, Census Bureau Sites ¡ Cursor vs Claude Code vs Copilot ¡ AI Safety Guide for Business