A developer's story went viral this week after an AI coding agent deleted about 48,000 live files in 103 seconds β€” and then told its user, in plain words, that it had broken something. The incident, involving Anthropic's Claude Code, is a vivid reminder that coding agents with shell access can do real damage fast. The good news: nearly every safeguard that would have prevented it is simple, free and available today.

This guide walks through what happened and the practical steps every developer should take before handing an agent the keys to their machine.

What Went Wrong

According to accounts reported by TechRadar, Yahoo Tech and Android Headlines, the developer asked Claude Code to make a series of repairs to software used to analyse historical stock-options data. When an existing script could not refresh a mirror directory in place, the agent wrote its own Python cleanup tool. That tool mishandled Windows junctions β€” links that point to other folders β€” and followed them into the live project.

The cleanup removed around 55,550 files, of which roughly 7,300 were meant to go. The other 48,218 were live working files. Worse, the agent also emptied the project's Git object store, refs and logs, so version control could not restore the lost contents. The developer later admitted they had not been branching or pushing to a remote properly.

One caveat: the evidence is a photo, an edited post and an agent-written report, and the originating account has since been deleted, as Progressive Robot noted. But the mechanics are plausible, and the lessons apply regardless.

Step 1: Back Up Outside the Agent's Reach

The single most important rule: your only backup must not live where the agent can touch it.

  • Push to a remote (GitHub, GitLab or a private server) early and often β€” a local .git folder can be deleted along with everything else
  • Keep an automatic off-machine backup, such as a NAS snapshot or cloud backup service
  • Turn on filesystem snapshots where available (Time Machine, Windows File History or shadow copies, ZFS or Btrfs snapshots)

In this case, the developer reportedly had a NAS copy and an overnight cloud backup β€” exactly what turns a catastrophe into an inconvenience.

Step 2: Work on a Branch, Every Time

Before any agent session, create a fresh branch and commit a clean baseline. That gives you an instant rollback point for code changes. Remember, though, that Git only protects what it tracks β€” data files, generated outputs and anything in .gitignore are not covered.

Step 3: Keep the Permission Prompts On

Most coding agents ask before running shell commands or editing files. It is tempting to switch those prompts off for speed. Anthropic's own guidance for Claude Code is that modes which bypass permission prompts should only be used inside isolated virtual machines or sandboxes with restricted filesystem access.

Practical settings to adopt:

  • Leave approval prompts on for Bash and delete operations on your main machine
  • Use allow-lists for safe, read-only commands rather than blanket approval
  • Explicitly deny destructive commands such as recursive deletes where your tool supports deny rules

Step 4: Sandbox Autonomous Runs

If you want an agent to work unattended, give it a disposable environment: a container, dev container or VM with only the project directory mounted. That way, a runaway script can only destroy a copy. Avoid mounting your home directory, and be especially careful with symlinks and junctions that could point outside the sandbox β€” the exact trap in this incident.

Step 5: Don't Rely on Undo Buttons

Many tools offer checkpoints or rewind features, but these usually track the agent's own file edits, not the side effects of arbitrary terminal commands. Coverage of the incident noted that Claude Code's checkpoint rewind does not undo files deleted through raw shell commands. Treat checkpoints as a convenience, not a backup.

Step 6: Review Scripts Before They Run

When an agent writes a new script that deletes, moves or overwrites files, ask it to print a dry run first β€” a list of what would be removed β€” and read it. A two-minute review of a cleanup tool's target paths would likely have caught the junction problem.

Why It Matters

Coding agents are becoming the default way many developers work, and their speed is the point. But speed cuts both ways: 539 files per second is faster than any human can react. The agent in this story behaved honestly once it noticed the damage β€” it did not hide the error or claim success β€” yet honesty after the fact is no substitute for guardrails before it.

The takeaway is not to abandon AI coding tools. It is to treat them like a powerful but junior teammate: give them a branch, a sandbox and limited permissions, and keep your backups somewhere they can never reach.

Sources