An incident shared on Reddit has alerted those who use artificial intelligence assistants for programming. A user reported that an agent from Claude Code, Anthropic's tool for AI-assisted development, deleted 48,218 files from their project on Windows and wiped the Git history in just 103 seconds.
The case is significant because it exposes a very specific technical flaw that could recur on any Windows machine where an AI agent is allowed to operate without sufficient safeguards. This was not an isolated case of defective software, but rather a combination of an operating system shortcut and a security check that failed to detect it in time.
What the affected user reported
The story was published on September 20, 2026, on the r/ClaudeAI forum. As explained, the individual works in the financial sector, is not a programmer, and was using Claude Code to develop a testing program related to stock market operations.
The original post was later removed, though comments containing the command given to the agent and the report it generated after the incident remained available. All available information comes from that account and the report; there is currently no independent third-party verification.
The command that triggered the problem
The user had authorized fifteen fixes on what they described as isolated copies of their project. One of those tasks involved rebuilding a test mirror, which is an auxiliary copy of the original project.
To execute that task, the main agent launched several sub-agents. One of them wrote a script intended to delete the old mirror, which contained 7,332 files and 614 internal Windows links, technically known as junctions, that pointed directly to the actual project.
The report generated by the agent itself begins with a direct warning: it notes that something has broken and asks the user to stop and read before continuing.
The technical cause: a shortcut the system did not recognize
A Windows junction is, in essence, a folder that acts as a shortcut to another location in the system. The deletion script was supposed to identify and skip those links to avoid affecting the original project, but the check it used was unable to detect them correctly.
The problem lies in a Python language function called os.path.islink(), which on Windows systems returns "false" when applied to a junction, even though it is technically a link. Because it did not recognize it as such, the program entered those linked folders and deleted their content as if it were a legitimate part of the copy that needed to be removed.
The protection included in the script only covered files located right at the root of each junction, but not the folders and files contained within them, which is precisely where the damage was concentrated.
Technical verification of the flaw
In tests performed on a machine with Windows and Python 3.14, this behavior is confirmed: the os.path.islink() function returns "false" when applied to a junction, while the os.path.isjunction() function, designed specifically for this type of link, does return "true." The same behavior can be observed from the Windows Command Prompt using the dir /AL command, which identifies these folders with the JUNCTION label.
The scope of the deletion, in numbers
According to the log generated by the process itself, a total of 55,550 files were deleted. After subtracting the 7,332 corresponding to the mirror that was intended to be deleted, 48,218 actual files were affected—a calculation performed by an external reviewer and also reported by the specialized outlet Cyber Security News.
The deletion occurred between 10:10:31 PM and 10:12:14 PM, Eastern Time, meaning it happened within a window of 103 seconds.
The impact was not limited to project files. The internal Git folders corresponding to objects, refs, and logs were left completely empty, meaning the git log command could no longer find any previously saved changes. The Git index survived, but without the actual content it referenced.
According to the agent's report, the only things that remained intact were existing backups and files located outside the main project folder. The user indicated they would attempt to recover the information through Windows backups and, if that were not enough, through their copy stored on the iDrive service. No subsequent information has been published regarding the final outcome of that recovery.
What Anthropic says about these risks
Anthropic's official documentation for Claude Code does not refer to this specific case, but it does establish several relevant rules for understanding the context of the incident.
- The mode that allows bypassing all permission requests, known as bypassPermissions, is intended only for isolated environments, such as containers or virtual machines, where an eventual agent error cannot cause real damage. It has not been confirmed which permission mode the affected user was using in this case.
- Claude Code checkpoints, which can be activated using the /rewind command, are not designed to revert actions executed directly on the file system, such as deletion or file movement commands. They also do not replace the version control offered by Git.
- When running natively on Windows, i.e., without using the WSL2 subsystem, Claude Code executes commands without the additional isolation layer that it applies on macOS, Linux, and WSL2 systems.
What to learn from this case if you use AI agents on Windows
The incident offers three practical lessons for anyone working with Claude Code or other similar agents on Windows.
The first is to always maintain a backup that the AI agent cannot modify or delete, ideally on another physical disk or in a cloud service. According to the agent's own report, it was precisely that type of external copy that allowed some of the information to be preserved.
The second recommendation is to use Git with a remote copy hosted on an external server, such as GitHub, since in this case, the local copy of the project's change history was completely lost.
The third is to avoid granting full permissions to an AI agent over folders containing information that cannot be lost, especially when there are internal operating system links, such as Windows junctions, which can generate unexpected behaviors.
Frequently Asked Questions
What is Claude Code?
It is a tool from Anthropic that allows for programming with artificial intelligence assistance, executing development tasks through automated agents capable of writing and running code.
How many files were lost in the incident?
According to the calculation based on the process log, 48,218 actual project files were deleted, after discounting the 7,332 files corresponding to the mirror copy that was intended to be deleted.
Why did the system not detect the error before deleting the files?
The Python function used to detect links, os.path.islink(), does not correctly recognize Windows junctions, so the deletion script treated those links as normal folders instead of shortcuts that should have been avoided.
Could the lost information be recovered?
The user indicated they would attempt to recover it through Windows backups and, if that were not enough, through a copy stored on the iDrive service. No subsequent information has been published regarding whether the recovery was successful.
Could the Claude Code /rewind command have prevented the damage?
No. According to Anthropic's own documentation, checkpoints activated with /rewind do not undo direct actions on the file system, such as deletions performed by delete commands, nor do they replace Git version control.
Does this problem only affect Windows users?
The specific flaw is related to the behavior of Windows junctions and a Python function that does not detect them correctly on that system. Furthermore, Claude Code executes commands without the additional isolation layer that it offers on macOS, Linux, and the WSL2 subsystem.

