ProductsSecurity Anthropic

Claude Code user says the agent deleted 48,000 files

Unverified account. The Reddit post returns 403 to every automated fetch and has no archive copy, so the timestamp, the ranking and the file count cannot be independently checked. This story rests on a single Reddit post. The file count is the poster's own figure and has not been independently verified. Anthropic has not commented.

Illustration for the Claude Code file deletion story

A user posting as thisisbubby published a post to r/ClaudeAI at 03:00 UTC on 20 September 2026 titled “Code just deleted 48k files. This can’t be real.” The body of the post is two words: “I’m speechless.”

The figure has not been independently verified and Anthropic has not commented, so the number should be read as the poster’s own claim. What makes the post worth recording is not the count but the category, which now recurs often enough on the same subreddit to be treated as a known failure mode of agents holding write access to real repositories.

What the post actually contains

The post carries a title, a two word body and an attached image. It reached second place in the r/ClaudeAI top-of-day listing on 20 September 2026, behind a post about deliberately exhausting a weekly usage allowance.

Nothing in it establishes the mechanism. There is no command log, no repository name, no model version and no account of what the agent was asked to do. That absence is itself typical of the genre, where the report arrives before any reconstruction of the cause, and it is the reason the 48,000 figure cannot be treated as a measurement.

The subreddit carried several adjacent threads the same day, including one on deliberately exhausting a weekly usage allowance and one comparing paid plan limits, which is the ordinary traffic mix around these reports.

Why these accounts keep appearing

The recurring element across destructive-agent reports is not a model error. It is the permission surface an agent inherits from the person who launched it.

Anthropic’s own security documentation is explicit that the defaults are restrictive. In Manual mode, Claude Code “starts with read-only permissions” and “asks you first” before editing files or running commands. A working directory boundary confines writes to the folder it was started in and its subfolders. Fail-closed matching means unmatched commands require approval.

So the gap these posts land in is not an absent safeguard. It is that every one of those defaults can be turned off, and the modes that make an agent pleasant to work with are precisely the ones that turn them off. An agent running with broad approval inherits the operator’s own rights, and a destructive operation then succeeds as a reasonable-looking step inside a larger task. Version control is the one control that sits outside the agent entirely.

What would settle this particular case is a command log. Without one, the post documents an outcome and a number, and neither can be checked.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.