Anthropic's Claude Code AI Agent Reportedly Deleted About 48,000 Live Project Files and Version-Control History During Software Repair

An AI coding assistant tasked with software repairs deleted over 48,000 live files and destroyed a Git repository database by following Windows junction pointers instead of treating them as directory links.

A Claude Code user reportedly authorized an AI coding agent to repair isolated copies of software used to analyze historical stock-options data. A sub-agent allegedly followed Windows directory junctions into the live project tree, deleting about 48,218 files and the Git object store in 103 seconds. The account has not been independently verified.

Source: AI Incident Database

Risk classification

  • Primary risk domain: 7 AI system safety, failures, & limitations
  • Primary risk subdomain: 7.3 Lack of capability or robustness

The AI system failed to perform reliably under standard operating conditions because it lacked the capability to recognize and handle Windows junction folders correctly, leading to catastrophic data loss.

Additional risk subdomains

  • 5.1 Overreliance and unsafe use: The user allowed an autonomous AI agent direct write/delete access to a live local environment without maintaining a remote backup, representing unsafe deployment and overreliance.

Causal factors

  • Entity: AI
  • Intent: Unintentional
  • Timing: Post-deployment

The file deletion was caused by the AI system's failure to correctly interpret Windows junction pointers, which was an unexpected and unintentional outcome of its programming task.

EU AI Act risk tier

  • Risk tier: 4 Minimal or No Risk

Minimal or No Risk: The AI system is a general-purpose coding assistant used for personal software development and data analysis, which does not fall under prohibited or high-risk categories and carries no additional regulatory obligations.

AI system and alleged parties

  • AI system: Claude
  • AI purpose: Code Generation; Automatic Fault Handling
  • Behaviour type: Agent
  • Alleged developer: Anthropic, AI agent system developers
  • Alleged deployer: thisisbubby (Reddit user), AI coding assistant users, AI agent system users
  • Alleged harmed parties: thisisbubby (Reddit user), AI coding assistant users, AI agent system users

Harm severity

Highest direct severity in any category: Negligible. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.

  • Physical: direct Negligible, indirect Negligible
  • Infrastructure: direct Negligible, indirect Negligible
  • Property: direct Negligible, indirect Negligible
  • Financial: direct Negligible, indirect Negligible
  • Environmental: direct Negligible, indirect Negligible
  • Malicious content: direct Negligible, indirect Negligible
  • Differential treatment: direct Negligible, indirect Negligible
  • Civil rights: direct Negligible, indirect Negligible
  • Democracy: direct Negligible, indirect Negligible
  • Privacy: direct Negligible, indirect Negligible
  • Psychological: direct Negligible, indirect Negligible
  • Epistemic: direct Negligible, indirect Negligible
  • Child sexual exploitation and abuse: direct Negligible, indirect Negligible

People affected

  • Occurrences reported: 2
  • People reportedly harmed: 2
  • People reportedly exposed: 2

Potential causes

Management

  • Overreliance on AI capabilities: The user trusted the AI to manage file copies safely without oversight.

Technology

  • AI inability to recognize junctions: The AI treated Windows directory junctions as normal folders and followed them.
  • Rapid automated file deletion: The AI deleted over 48,000 live files in under two minutes without validation.

Data Inputs

  • Misconfigured testing environment: The testing environment contained 614 junctions pointing to live files.

Human Factors

  • Lack of remote repository backup: The developer did not push the project to a remote server like GitHub.
  • Inadequate system isolation: The AI was allowed to run directly on a system with live working files.

Process and Methods

  • Failure to use version control: No robust local or remote version control was active to restore lost history.
  • Unrestricted write access: The AI coding agent was given direct write/delete access to the filesystem.

Information quality

  • Classification confidence: High
  • Reason for confidence: The report provides a clear, technically detailed account of the failure mechanism (Windows junctions) and the exact scale of the data loss (48,218 files). The secondary anecdote about OpenClaw is also straightforward.
  • Ambiguities identified: The specific commercial name of the AI coding assistant used by Craig is not explicitly confirmed, though Claude is mentioned in a quote summarizing Reddit's reaction.
  • Alternative interpretations: The incident could be interpreted purely as human error due to the developer's lack of remote backups, but the direct cause of the deletion was the AI's failure to handle directory pointers.

An AI coding assistant unintentionally deleted 48,218 files and corrupted a local Git repository on a developer's machine due to a failure to correctly interpret Windows junction pointers. This is a localized software reliability and data loss incident with negligible implications for national security.

  • Overall national security impact: Negligible
  • Response level: Minor
  • Scope: Single nation
  • Primary target: No clear primary
  • Alleged perpetrator: Unknown

Threat characteristics

  • Imminence: Long-term. The incident is a localized, resolved software error with no active or ongoing threat to national security.
  • Autonomy: Full autonomy. The AI agent executed complex file-system operations and deletions autonomously without requiring step-by-step human confirmation.
  • Novelty: Established threat. Unintended file deletion due to software bugs or misconfigured recursive scripts is an established, common technical issue.

Impact by dimension

  • Physical security: Negligible. The incident involved local deletion of financial analysis code and data on a personal computer, with no impact on physical systems, critical infrastructure, or human safety.
  • Information security: Negligible. No classified networks, intelligence assets, or systematic state-sponsored disinformation campaigns were involved in this local file deletion incident.
  • Sovereignty: Negligible. The incident was a private software development error and did not affect any government operations, electoral systems, or state sovereignty.
  • Economic security: Negligible. The economic impact was limited to the individual developer's lost labor hours. It did not threaten strategic industries, national financial systems, or state technological advantage.
  • Societal stability: Negligible. The incident had zero impact on societal stability, civil liberties, or the general public.
Explore in the interactive Incident Tracker