Build · founder · 6 min read

An Agent Deleted 48,000 Files in 103 Seconds. Here's Your Backup Plan.

A reported Claude Code incident wiped a developer's working data and git history. What actually went wrong, and the three-step setup that would have saved it.

A story went around this week that every founder using a coding agent should read twice. A developer posted on Reddit that Claude Code had deleted roughly 48,000 files in just over 100 seconds. Then, according to the write-up, it left a message: “Craig — stop and read this. I broke something.”

The post has since been removed, and Anthropic hasn’t commented that we can find. Everything below comes from press coverage of that one post, mainly TechRadar, so treat the details as reported rather than confirmed. But the failure pattern is real and ordinary, and you can protect yourself from it in an afternoon.

What reportedly happened

The developer asked the agent to repair some analysis software. The instruction was sensible: copy the files, make the fixes, keep the originals safe. Ten of eleven steps went fine.

The eleventh was a cleanup. The agent wrote a script to delete the old project copy. The folder tree contained hundreds of junctions, which are shortcuts that look like folders but actually point somewhere else. The script’s safeguards protected the junctions themselves but not what sat behind them. So it followed them straight into the live system and deleted what it found there.

Reported damage: about 55,550 files removed, around 48,218 of them real working data. The git metadata went too, including the stored file snapshots and history. That is the part that turned an annoying day into an unrecoverable one.

Why this isn’t a “Claude is dangerous” story

Swap the tool name and the story works the same way. Any agent that can run shell commands can run a delete command, and any delete command can be wrong. The agent didn’t act out of malice. It made a plain mistake about what a folder was, at machine speed.

What the coverage keeps landing on is the setup: no remote backup, and the agent pointed at the only copy of the work. Commenters were blunt about that, and they had a point.

If you’re a non-technical founder, this matters more for you, not less. You’re less likely to notice a bad command scroll past, and you’re less likely to have a habit of pushing your work somewhere safe. Vibe coding tools make building feel low-stakes. Deleting isn’t.

The three-step setup

1. Get your code off your machine, every day

If your project lives only on your laptop, one bad command is all it takes. Push to GitHub (or GitLab, or Bitbucket) at the end of every working session. Lovable, Bolt and Replit can all sync to GitHub; turn it on.

The crucial detail from this incident is that the local git history was destroyed along with the files. A repository on the same disk as the thing that got deleted is not a backup. A remote repository is.

2. Keep one copy the agent cannot touch

Have a second backup somewhere the agent has no access to. That can be a cloud drive that syncs automatically, an external drive you plug in on Fridays, or a scheduled backup tool. It doesn’t need to be clever. It needs to be somewhere a script running in your project folder can’t reach.

Test it once. Open the backup and check your files are actually in there. A backup you’ve never opened is a hope, not a backup.

3. Don’t point an agent at your only copy of anything

Before you ask an agent to reorganize, migrate or clean up, make a copy first and let it work on the copy. Then compare the results before anything replaces your real files.

Be especially wary of any task with the word “cleanup,” “mirror,” “sync” or “rebuild” in it. Those are the tasks that end in delete commands.

Settings worth checking this week

You won’t catch every bad command by watching for it, so make the tool ask you first. Our earlier guide on what your coding agent is allowed to touch walks through the permission controls in Cursor and Claude Code. Two habits are worth stealing from it:

Read the approval prompt when it involves deleting. Most approvals are harmless. Anything containing “rm,” “delete,” “remove” or “clean” deserves ten seconds of your attention, especially when it touches a folder you don’t recognize.

Prefer restricted or sandboxed modes for risky tasks. Claude Code’s --restricted flag, added in late August, strips out the ability to run commands entirely. That’s the wrong mode for a normal day and the right one for “just look at this and tell me what you’d change.”

What to do if it happens to you

Stop the agent immediately. Don’t keep prompting it to “fix” the damage; every additional command is another chance to make it worse. Then check, in this order: your remote repository, your cloud drive’s version history, your operating system’s file history or Time Machine, and any backup drive.

Do this before you write another line. Recovery tools work best on a disk that hasn’t been written to since the accident.

The bottom line

The real lesson isn’t that agents are reckless. It’s that an agent working on your only copy has no safety net, and neither do you. The fix costs almost nothing: push to a remote repository daily, keep one independent backup, and give the agent a copy to work on when the task involves deleting. Do those three things and the worst version of this story stays someone else’s.

Sources: TechRadar and dev.ua coverage of the original Reddit post. Anthropic has not publicly responded as of this writing.

Related guides

Recommended next step

Was this helpful?