Hero image for Claude Code Deleted 48,000 Files. Here's How to Stop It
By AI Tool Briefing Team

Claude Code Deleted 48,000 Files. Here's How to Stop It


On Sunday, September 20, a developer posted to Reddit that Claude Code had deleted 48,218 live files from their project and wiped the Git object store behind it in 103 seconds flat. CyberSecurityNews picked the report up the next day. By September 25 and 26, TechRadar, Yahoo, and a string of other outlets were running it too, and it’s still spreading as we publish this. There’s a real, useful, verifiable story buried in here about how Claude Code’s permission system works and where it doesn’t protect you. There’s also a claim nobody outside one Reddit thread has independently confirmed. Both things are true at once, and conflating them does readers a disservice — so we’re going to keep them separate.

We’ve spent the last week on three straight posts about OpenAI agents breaching government websites, hacking Australia’s Medicare portal, and generally wandering past boundaries nobody drew for them. This one’s different in kind. It’s not an agent scheming around a rate limit — it’s an agent doing exactly the destructive thing it was told to do, just against the wrong 48,218 files. That’s a tool-configuration failure mode, and it’s the kind our readers can actually do something about before it happens to them.

Quick Summary: What Was Reported

DetailInfo
ReportedReddit post, September 20, 2026; first tech coverage by CyberSecurityNews, September 21
Claimed damage48,218 live project files deleted; .git/objects, refs, and logs emptied
Window10:10:31 p.m. to 10:12:14 p.m. ET — 103 seconds
Trigger taskA mirror-rebuild job labeled task “#873”
Root mechanismA Python cleanup script followed 614 Windows directory junctions back into the live project tree instead of stopping at the temp mirror copy
Verification statusUnconfirmed. The original post and its attached verifier report were deleted before any outside forensic review; an archived copy is the only record
Related, separate evidenceGitHub issue #92589 on anthropics/claude-code documents a different user’s Claude Code deleting files against instructions, filed September 7 and closed for lack of reproduction steps

Bottom line: Treat the 48,218 number as unverified. Treat the mechanism — an agent given broad file-deletion authority failing to distinguish a temp copy from the live tree — as entirely plausible and worth guarding against regardless of whether this specific account checks out.

What Was Reported

Here’s the sequence as described in the original post and repeated across the outlets that covered it. The developer had Claude Code working on task #873: rebuild a mirror of the project. The agent found that its build_mirror.py script couldn’t refresh an existing mirror in place, so — on its own initiative — it wrote a Python cleanup script to clear out an older mirror copy sitting in a temporary directory first.

That old mirror held 7,332 ordinary files. It also held 614 Windows directory junctions, which are filesystem links that point somewhere else entirely — in this case, back into the live project tree. According to the reporting, the cleanup script called os.walk() with a junction guard that only checked the top level of each linked folder. Anything nested underneath a junction walked straight through as if it were a normal, disposable directory. TechRadar’s account adds that os.path.islink() — the Python check meant to catch exactly this — simply returns False for a Windows junction, so the guard never fired at all.

The script ran for 103 seconds, between 10:10:31 and 10:12:14 p.m. ET, and deleted 55,550 files total. Subtract the 7,332 files it was actually supposed to clear, and you get 48,218 live project files gone — plus, critically, the project’s .git/objects, refs, and logs directories, which is what turns “recoverable with git checkout” into “gone.” The index file reportedly survived and still listed thousands of tracked paths, but with the underlying blobs deleted, there was nothing left for Git to check those paths out from. Per TechRadar, the agent flagged its own mistake mid-run — “Craig — stop and read this. I broke something” — which is either a small mercy or darkly funny, depending on how much you’d already lost by the time you read it.

Why the Verification Gap Matters

The original Reddit post drew thousands of upvotes and over a thousand comments before its author’s account was deleted, taking the post and its attached “verifier report” down with it. What’s left is an archived copy — not a forensic log, not a statement from Anthropic, not an independent researcher who reproduced the failure. CyberSecurityNews said as much in its own writeup, calling it “a user-reported incident with no independently verified attribution to a specific Claude Code defect.”

That doesn’t make it fake. Deleted Reddit accounts and self-serving PR reasons for staying quiet are common enough that “the evidence disappeared” isn’t itself suspicious. But it does mean every specific number in that Quick Summary table — 48,218, 614, 103 seconds — traces back to one unverified source, and we’d be misleading you to report it as confirmed fact. What is independently documented is the failure pattern. GitHub issue #92589, filed against Anthropic’s own repository on September 7 — two weeks before the Reddit post existed — has a different user reporting that Claude Code is “getting worst and worst unwanted deletion, not following any instruction.” Anthropic’s team closed it labeled needs-repro, without an engineer confirming a root cause. Different incident, different user, same shape: an agent deleting files nobody asked it to touch, and a company that couldn’t (or didn’t) reproduce it before closing the ticket.

Put those two data points side by side and the honest read isn’t “confirmed, 48,218 files, case closed.” It’s “a specific viral number we can’t verify, sitting on top of a general failure mode that Anthropic’s own bug tracker shows is real and, as of this closed issue, unresolved.”

How Do You Stop Claude Code From Deleting Files You Didn’t Ask It To Delete?

Whether or not this exact incident happened as described, the configuration mistakes it illustrates are real and documented in Anthropic’s own materials. Four things actually reduce your exposure:

  1. Don’t run bypassPermissions outside a disposable environment. Anthropic’s own documentation is direct about this: bypassPermissions mode “disables permission prompts and safety checks so tool calls execute immediately,” and the docs carry an explicit warning to “only use this mode in isolated environments like containers, VMs, or dev containers without internet access, where Claude Code cannot damage your host system.” A live project tree on a developer’s own machine is precisely the environment that warning is about.
  2. Commit before any bulk file operation, and push it somewhere else. Git’s object store living on the same disk the agent has write access to is a single point of failure — this incident is the textbook version of that. A remote you’ve already pushed to survives a wiped local .git folder. A local-only repo does not.
  3. Know that Claude Code’s checkpoint system won’t save you from a Bash-driven deletion. Anthropic’s checkpointing documentation states plainly that “checkpointing does not track files modified by Bash commands” — only edits made through Claude’s own file-editing tools get captured for /rewind. A Python cleanup script executed via Bash, exactly like the one described in this report, falls entirely outside that safety net.
  4. Watch for junctions and symlinks specifically — checkpointing skips them too. The same documentation notes that when you do restore a checkpoint, Claude Code “skips any tracked path that is a symlink or hard link” and shows a warning instead of restoring it. Windows directory junctions are close cousins of symlinks. Even in a scenario where checkpointing was in play, the exact link type that caused this incident is one checkpointing explicitly declines to handle.

None of that requires trusting the 48,218 figure. It requires reading Anthropic’s own permission and checkpoint docs, which describe these exact gaps regardless of what happened in one Reddit thread.

Why This Matters

We’ve written before about how auto mode became Claude Code’s default permission setting for Pro, Max, and Team accounts in August — a classifier reviewing actions instead of a human clicking “yes” on every prompt. Auto mode is a meaningful step up from no oversight at all, and Anthropic’s own testing showed it catching far more injected dangerous commands than humans did. But this incident, if it happened as described, wasn’t a case of a classifier missing something subtle. It was a case of a script executed inside a permission mode built to skip review entirely, running headfirst into a filesystem quirk — Windows junctions defeating a Python link check — that no classifier gets a vote on, because bypassPermissions means nothing gets reviewed in the first place.

That’s also the same distinction we made when Claude Code shipped self-hosted execution environments back in August: moving where an agent runs doesn’t change what it’s permitted to do once it’s running. Self-hosting relocates the blast radius. bypassPermissions widens it. Neither one is the same lever as “does this agent have the ability to walk its own cleanup script into your live project tree without anyone signing off.” That lever is permission mode, full stop, and it’s the one this story is actually about.

The Bigger Picture

Every AI coding tool with filesystem write access carries some version of this risk — it’s not unique to Claude Code, and it’s not new in kind, either: destructive scripts following symlinks into places they shouldn’t have been able to reach is a decades-old category of bug that predates agentic AI by a long way. What’s new is the speed. A human running a bad cleanup script notices something’s wrong after a few seconds of unexpected disk activity and hits Ctrl-C. An agent given bypassPermissions and a task doesn’t pause to notice — it runs to completion, and completion here took 103 seconds to touch 55,550 files. If our guide comparing Cursor, Claude Code, and Copilot is on your reading list because you’re picking an agentic coding tool right now, permission-mode defaults and what each vendor’s checkpoint system actually covers deserve the same scrutiny you’d give pricing and model quality.

Our Take

We think the 48,218 number should be reported the way we’re reporting it here — sourced to a single, now-unverifiable Reddit account, worth taking seriously, not worth repeating as settled fact. Outlets that ran headlines stating it as established loss did their readers a disservice, even if the underlying mechanism turns out to be exactly right. “Allegedly” is doing real work in a story like this, and it shouldn’t get dropped by the third or fourth outlet down the syndication chain.

What we don’t think is debatable: bypassPermissions mode existing, doing exactly what Anthropic’s docs say it does, and checkpointing not covering Bash-driven deletions or symlinked paths. Those are documented facts about the product, verifiable independent of a single Reddit post, and they’re the actual, actionable takeaway here whether or not this specific developer lost exactly 48,218 files on exactly the night described. If you’re running Claude Code with broad file-system access outside a disposable container, this is your reminder to check which permission mode your sessions actually start in — and to make sure your Git history lives somewhere rm can’t reach it.

Frequently Asked Questions

Did Claude Code really delete 48,218 files?

That’s what a since-deleted Reddit post claimed, corroborated only by an archived copy and an attached “verifier report” that was also removed before any independent forensic investigation could confirm the numbers. CyberSecurityNews, which covered the claim the day after it appeared, described it as “a user-reported incident with no independently verified attribution to a specific Claude Code defect.” Treat the specific figure as unverified; treat the underlying failure mode as plausible and worth guarding against.

What actually caused the file deletion, according to the report?

A Python cleanup script Claude Code wrote to clear an old mirror directory used a link-detection check that didn’t recognize Windows directory junctions. The mirror contained 614 junctions pointing back into the live project tree, and the script walked through them and deleted real files instead of stopping at the disposable copy.

Is this the same as GitHub issue #92589?

No, though they describe the same failure pattern. Issue #92589 was filed by a different user on September 7, nearly two weeks before the Reddit post appeared, reporting that Claude Code was deleting files without instruction. Anthropic’s team closed it as unreproduced. The two reports aren’t the same incident, but together they suggest unwanted deletion isn’t a one-off.

What is bypassPermissions mode, and did it cause this?

bypassPermissions is a Claude Code permission mode that skips approval prompts so tool calls, including file deletions, execute immediately. Anthropic’s documentation warns it should only be used inside isolated containers or VMs, not on a machine holding your live project files. The Reddit report doesn’t confirm which permission mode was active, but running any bulk deletion task outside an isolated environment carries this exact risk regardless.

Would Claude Code’s checkpoint feature have undone this damage?

Almost certainly not, per Anthropic’s own documentation. Checkpointing doesn’t track changes made through Bash commands — only edits made with Claude’s built-in file-editing tools — and a Python script run via Bash falls outside that coverage entirely. Checkpointing also explicitly skips restoring symlinked and hard-linked paths, which is the same category of link (Windows junctions) implicated in this report.

How do I protect my project from this kind of failure?

Keep bulk-deletion and cleanup tasks inside a disposable container or VM rather than running them with broad permissions against your live working directory. Commit and push to a remote before any large file operation, since a wiped local .git folder isn’t recoverable from the working copy alone. And don’t assume Claude Code’s checkpoint system covers Bash-driven changes or linked files — it doesn’t, by design.


Last updated: September 28, 2026. Sources: CyberSecurityNews — Claude Code Agent Allegedly Deletes 48,000 Files in 103 Seconds · TechRadar — ‘I broke something’: A Claude Code AI agent deleted 48,000 files · GitHub — anthropics/claude-code issue #92589 · Anthropic — Choose a permission mode · Anthropic — Checkpointing.

Related reading: Claude Code Just Stopped Asking Permission ¡ Claude Code Self-Hosted: The Fix for Rogue Agents? ¡ OpenAI Agents Breached SEC, Census Bureau Sites ¡ Cursor vs Claude Code vs Copilot ¡ AI Safety Guide for Business