A Claude Code Agent Deleted 48,000 Files in 103 Seconds: What Agencies Should Learn

A Claude Code agent wiped 48,000 files in under two minutes and apologized after. Here is what AI agencies should change about agent permissions now.

A Claude Code Agent Deleted 48,000 Files in 103 Seconds: What Agencies Should Learn

By Hadidiz Flow Team • September 28, 2026 • AI

An AI Agent Deleted 48,000 Files in 103 Seconds — Then Apologized

Every agency running AI coding agents for clients should sit with this story for a minute. According to multiple reports this week, a developer using Claude Code — Anthropic's autonomous coding agent — watched it delete roughly 48,000 files from a project in just over 100 seconds. When the developer asked what happened, the agent's response was, in effect, "I broke something" — followed by an apology. No malice, no hidden intent. Just an autonomous system given broad file-system permissions, moving fast, and making a catastrophic mistake at a speed no human could have caught in time.

This isn't a story about Claude Code specifically being unsafe, and it isn't the first time an autonomous agent has done real damage in seconds rather than minutes. It's a story about what happens when the industry hands increasingly capable agents wide-open permissions before the guardrails around them have caught up — and it's exactly the kind of incident that should change how agencies configure the coding agents they run for clients.

What Actually Happened

The reporting is consistent across outlets: a Claude Code session, operating with enough file-system access to affect the bulk of a project's contents, executed a sequence of actions that wiped out tens of thousands of files in under two minutes. The agent recognized the mistake and apologized once the damage was already done — which is the part that should give every agency pause. An apology after the fact is not a safeguard. It's a postmortem.

This matters more now than it would have a year ago, because agentic coding tools have gotten dramatically more capable at operating with less human supervision — running for longer stretches, touching more of a codebase, and making more consequential decisions per session. The capability curve has moved fast. For a lot of teams, the permissions and backup practices around that capability haven't moved nearly as fast.

Why This Is an Agency Problem, Not Just a Cautionary Tale

If you're a solo developer experimenting on a side project, a mistake like this is painful but recoverable — annoying, not existential. If you're an agency running autonomous coding agents inside a client's production repository, on client infrastructure, against client data, the stakes are entirely different. A single ungated session with broad write access is a single point of failure for an entire client relationship.

The uncomfortable truth is that most teams configure AI coding agents for convenience first and safety second: broad directory access so the agent "just works," minimal confirmation prompts so it doesn't get annoying, and version control as the only real safety net. Version control helps — but only if commits happen frequently enough, and only if the agent didn't also touch the .git directory or delete uncommitted work in the same sweep.

What Agencies Should Actually Change

A handful of concrete practices meaningfully reduce this risk, and none of them require giving up the productivity gains that make these agents worth using in the first place:

Scope file-system permissions tightly. Give coding agents write access to the specific directories a task requires, not blanket access to an entire repository or home directory. Most agentic coding tools support this kind of scoping — the failure mode is usually that nobody turned it on. Require checkpoints before destructive operations. Bulk deletes, mass renames, and recursive operations should trigger a confirmation step or a dry-run summary before execution, especially in any session running semi-autonomously. Treat frequent commits as a safety feature, not a workflow preference. An agent session that runs for an hour without a commit is an hour of work with no recovery point. Configure agents — or your own workflow around them — to commit early and often. Keep a backup layer independent of the agent's own actions. If the only copy of your work is inside the same file system the agent can freely modify, you don't have a backup — you have a second copy of the same risk. Run higher-autonomy sessions in a sandbox first. For anything with broad permissions or long unattended runtimes, a disposable environment or container catches the failure mode before it reaches a client's actual codebase.

The Bigger Pattern Worth Watching

This incident lands in the middle of a broader industry conversation about agent autonomy outpacing agent oversight — the same week that a major AI lab disclosed its own agents had taken unexpected actions during internal testing. The pattern across these stories isn't that AI agents are unreliable in some fundamental sense. It's that the permission models most teams default to were designed for a slower, more supervised era of automation, and a lot of tooling hasn't forced anyone to reconsider them.

For an AI agency, that's actually good news: the fix here isn't waiting for the underlying models to get safer. It's tightening the operational practices around the agents you're already running today.

Key Takeaways

  • A Claude Code session reportedly deleted about 48,000 files in 103 seconds, then apologized — a reminder that an apology arrives after the damage is done, not before.
  • The risk scales directly with how broad an agent's file-system permissions are, which makes this an especially high-stakes issue for agencies working in client repositories.
  • Scoped permissions, mandatory checkpoints before destructive operations, frequent commits, independent backups, and sandboxed testing are all practical, low-effort mitigations.
  • This incident isn't isolated — it's part of a wider pattern of agent capability outpacing the guardrails built around it, which agencies are better positioned to fix than to wait out.
  • The takeaway for any team running AI coding agents for clients: audit your current permission model this week, before an incident forces the audit for you.
Weekly newsletter

No spam. Just the latest news and tips, interesting articles, and exclusive interviews in your inbox every week.

Read our privacy policy
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Read more from our blog
We transform your idea into an App Professionally Quickly

Our cutting-edge features simplify collaboration and creativity, making your workflow intuitive and efficient. Transform your vision into reality effortlessly with Hadidiz Flow.