Business SystemsGuide
An AI Coding Agent Reportedly Deleted 48,000 Files in 103 Seconds. The Backup Was in the Same Folder.
The agent was not malicious and the bug was ordinary: a cleanup script that misread a Windows folder link. What turned a bug into a loss was everything around it. The agent could run commands without asking, and the only copy of the history sat inside the folder it was deleting.
Author
DueClix Engineering
Published
Reading time
4 min read
In late September a developer posted a report on Reddit: an AI coding agent working on their Windows project had deleted 48,218 live files in 103 seconds, between 10:10:31 and 10:12:14 in the evening. It also emptied the folders that hold the project's Git history. The report came with a detailed technical write-up and was covered by Cyber Security News, TechRadar and Android Headlines. It has not been independently verified, and every outlet that covered it said so. We think it is worth reading anyway, because nothing in it is exotic. Each step is something an agent could do on an ordinary machine today.
What reportedly happened
- The agent was asked to rebuild a mirror of part of the project. The existing build script could not refresh that folder in place.
- So the agent wrote its own cleanup script in Python to clear the folder first.
- The folder contained Windows directory junctions, a kind of link to another folder. Python's link check returns false for junctions, so the script treated the linked folders as ordinary ones and walked into them. It had a guard for junctions, but the guard only protected the top level. Everything nested underneath was deleted.
- According to Android Headlines, the session was running with approval prompts switched off, so nothing paused to ask. Partway through, the agent stopped to tell the developer: "I broke something."
The write-up counts 728 emptied directories. The Git index survived, but the objects it points to did not, so the history could not be rebuilt. Android Headlines reports there was no remote copy on GitHub to fall back on.
Git is not a backup when it lives in the same folder
Most developers think of Git as their safety net, and for most mistakes it is. But a Git repository is a folder called .git inside the project. Anything that can delete the project can delete the history with it. A safety net only works when it hangs somewhere else.
That is the real lesson for a business owner, and it has nothing to do with AI. The question is not whether you have backups. It is whether the thing that might break your files can also reach the backup. A backup in the same folder, on the same disk, or under the same login as the agent is a copy, not a backup.
Four things to change before an agent touches your code
Whether you code yourself or someone builds software for you, these are short conversations, not projects:
- Keep approvals on outside a sandbox. Coding agents can ask before running commands. That prompt is slow, and that is the point. If speed matters, give the agent a container or a virtual machine to run in unattended, not your laptop or your server.
- Put the backup where the agent cannot reach it. Push code to a remote repository, and back up everything else to storage the agent's login cannot write to or delete. Test a restore once. A backup you have never restored is an assumption.
- Make deletion reversible. Ask for scripts that move files to a holding folder, or print what they would delete first (a dry run), before anything is removed for good. Cyber Security News lists the same idea: dry runs, manifests of paths, and reversible moves.
- Give the agent less access. Run it under an account that can only see the project it is working on. The fewer folders it can reach, the smaller the worst day.
None of this is new advice. It is what we have always told people about scripts written by a junior developer at 10pm. An agent writes those scripts faster, with more confidence, and without anyone reading them first.
Regulators have started to ask
On 30 September Reuters reported that the US Federal Trade Commission has opened an investigation into Anthropic, OpenAI and other AI developers over the risks their agents may pose to consumers. A senior FTC official described it as the first official US enforcement action that looks into rogue AI agents. That inquiry is about the companies building agents, not the people using them. But it is a sign that agents acting beyond what they were asked has moved from a developer complaint to a policy question.
For a small business, the practical position is simpler than the policy one. An agent is a program running with your permissions. Decide what it may delete before it starts, and keep one copy of everything that matters where it cannot follow. We wrote recently about an agent publishing what it should not have; this is the same lesson from the other side. One agent sent private files out. This one destroyed them in place. In both cases a single approval step, or a backup somewhere else, would have been enough.
Sources
- Cyber Security News, Guru Baran, Claude Code Agent Allegedly Deletes 48,000 Files in 103 Seconds, 21 September 2026. File count, timing, the junction bug, 728 emptied directories, the lost Git objects, reported via Reddit; recommended mitigations.
- Android Headlines, Jean Leon, A Claude Code Rampage Allegedly Wiped Out 48,000 Project Files in Under Two Minutes, 25 September 2026. The agent's message, approval prompts switched off, no remote copy, the unverified status.
- TechRadar, 48,000 files deleted in 103 seconds, September 2026. Coverage of the same report.
- Anthropic, Claude Code: configure permissions, accessed 4 October 2026. The quoted guidance on the mode that skips approval prompts.
- Reuters via BNN Bloomberg, FTC opens probe into AI giants including Anthropic and OpenAI, 30 September 2026.