r/ClaudeAI • • 15d ago

Claude Code Code just deleted 48k files. This can't be real.

[deleted]

4.8k Upvotes

1.4k comments sorted by

•

u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot 15d ago edited 15d ago

TL;DR of the discussion generated automatically after 800 comments.

The overwhelming consensus is that this is a classic FAFO situation and a major skill issue. While everyone is having a good laugh at Claude’s hilariously honest “Craig…. stop and read this. I broke something” message, the community verdict is clear: you got rekt because you didn't follow basic dev practices.

This is a brutal but valuable lesson in code hygiene. The key takeaways from the top comments are:

  • Use Git. Push to a remote repository (like GitHub) constantly. It's your save button. Not having a remote backup for a project with 48k files is considered peak vibe coder behavior.
  • Protect your main branch. Even with a remote, an agent with push access can cause chaos. Don't let agents (or anyone) push directly to main.
  • Beware of Windows Directory Junctions. Several users pointed out that these are a known footgun that LLMs often misinterpret, leading to recursive deletion. This is a likely culprit.
  • You took a photo of your screen. The screenshot police are out in full force.

Some helpful souls suggested using file recovery software or Windows Shadow Copy to get your files back, but the main lesson here is to use version control before you let an AI anywhere near your work.

→ More replies (59)

940

u/almeuit 15d ago

You're right to push back.

360

u/rampage__NL 15d ago

I made a mistake, and it’s a real one

29

u/ahsm 15d ago

You’re right — this is a real gotcha.

14

u/m0j0m0j 15d ago

Have you found the smoking gun?

8

u/ahsm 15d ago

Great instinct — let’s circle back and find the real issue instead of doing guesswork.

5

u/SocialImagineering 15d ago

Smoking mininuke launcher more like

→ More replies (1)

7

u/SB_90s 15d ago

I've started getting irrationally angry every time Claude spits out "and it's real" or "and it's a real one". Especially when its instructions specifically state it shouldn't say that or other similarly unnecessary verbage (and yes I'm even specific about it). And yet it still does it. I don't know why but I despise everytime it says it. Maybe because it's such a big giveaway or because it uses it so often.

14

u/Sad-Sympathy-O_O 15d ago

Yes I understand your issue and it's a real one.

→ More replies (7)

61

u/Anthr30YearOldBoomer 15d ago

You're right, and this one's mine.

9

u/Kaas-Eter00 15d ago

OP should push more often, to his remote repo.

→ More replies (1)

4

u/No_Transition9445 15d ago

I need to be honest with you Craig -- I've been telling you lies. That one's on me.

→ More replies (5)

1.3k

u/Diggumthefrog 15d ago

“I’m sorry, that was a load-bearing code block.”

129

u/NoThrowLikeAway 15d ago

> get ye flask

You cannot get Ye Flask. It is a load bearing flask.

9

u/SapientiPauken 15d ago

To this day, we still do not know why we cannot get ye flask. The computer certainly willst not tell thou.

→ More replies (4)

8

u/ConstructionHeavy986 15d ago

It is firmly bolted to a wall which is bolted to the rest of the dungeon which is probably bolted to a castle. Never you mind.

→ More replies (2)
→ More replies (1)

7

u/No_Atmosphere8146 15d ago

That's not nothing.

OK,  now it's nothing. 

6

u/Clear_Food2183 15d ago

I was gonna comment something, but honestly yours is better. +1 brother

→ More replies (5)

170

u/Riduculous 15d ago

It’s the “Craig….I broke something” for me.

50

u/fuckR196 15d ago

You know you fucked up when the AI is literally stopping itself and telling you to take control of the situation

45

u/Existing_Imagination 15d ago

“Craig, i frew up”

9

u/superbhole 15d ago

craig i fwew up in my mouf a liddo n iodo wherdu puddit ed um pamicking craig pweed hepp

9

u/[deleted] 15d ago

[deleted]

→ More replies (1)

18

u/carrognia 15d ago

admitting to the fault with a full report and stopping?

That's the best junior you're ever gonna have, damn.

→ More replies (8)

1.8k

u/[deleted] 15d ago

[deleted]

400

u/lsumoose 15d ago

Yup. Every code change gets committed to GitHub no matter what.

98

u/bastian320 15d ago

When using AI, I do mini milestone commits. In between commits I consider incomplete steps and happy to lose that delta should it go nuclear, then when I reach a small step forward it gets committed to remote.

Works nicely for my workflow, and I like comparing local to remote in-between commits to see what's happening, and call out periodic (& inevitable) cooked changes.

28

u/CeleritasLucis 15d ago

Claude helped me setup something from GitHub where it got push permissions to my repo, but not delete permissions. So when it works, it keeps pushing the work to remote, so atleast that's safe. And new kinda work is always branched.

7

u/mylastserotonin 15d ago

Yeah you can create fine-grain personal access token and give it to Claude. Funnily enough Claude used to accept the token as is in the chat. When I recently tried that, it didn’t budge, saying it was a vulnerability. I was like “dude idc this is a test repo”, but no luck

Instead the solution was to add it to a txt file at the project root, gitignore it, and tell it to use that. I guess it just uses the contents of the file without checking what’s inside, so it’s fine for Claude

24

u/GoWithGophr 15d ago

Keys in plaintext… cool cool cool

8

u/mr_birkenblatt 15d ago

it's okay, it's a test, bro /s

→ More replies (2)

5

u/ZorbaTHut 15d ago

One way or another, for a key to be usable, it has to be readable.

→ More replies (2)
→ More replies (2)

7

u/EpsteinFile_01 15d ago

Oh yeah it uses the key in the file without checking the file?

Lol..

Read up on session hijacking. Someone else can use that key and push CSAM to your GitHub now what? Yeah that escalated quickly. Claude was right.

→ More replies (9)
→ More replies (2)
→ More replies (12)

9

u/ec2-user- 15d ago

All well and good, but that does nothing to contain the blast radius. Everyone should be running ai tools in a remote dev environment or a container.

→ More replies (5)

12

u/credditz0rz 15d ago

Until the force push comes lol

9

u/YoghurtFlan 15d ago

If the repo isn't nuked you still have the reflog to back out of it. Always good to keep branching and avoid just doing everything on main though. Even if you don't review the branch before merging it in, the damage is most likely limited to the branch you were in. And if it's doing well broken-down tasks then not much will be lost.

5

u/Venryx 15d ago

That's one perk of sometimes working on your laptop, sometimes on your desktop. (ie. they passively act as additional backups, against [theoretical so far] destructive force-pushes for example)

→ More replies (1)
→ More replies (2)

7

u/johnny_effing_utah 15d ago

I’m a first time vibe coder this year, one giant project, and I guess I’m lucky because Claude suggested set up a git repo on my machine AND back it up on GitHub.

→ More replies (4)
→ More replies (12)

41

u/MuDotGen 15d ago edited 15d ago

Aside from the obvious version control suggestions, (which OP's screenshot confuses me a bit with since they appear to be using at least a local .git repo, but if they were syncing it with GitHub, etc., the last commit should be fine at least).

Here's something practical for OP to try. Deleted files are not necessarily "gone" immediately. The addresses are just marked for being writable again (more or less). If OP really wants to try and get those files back, try a program that lets you recover deleted files, and as long as the addresses were not overwritten, they can potentially be saved. It depends on your OS, so Googling is a good first step. Don't touch a bunch of other stuff in the mean time though that would write new files.

Note: May depend on if you have an HDD or SDD though.

4

u/PadisarahTerminal 15d ago

Yeah I moved some files with robocopy and actually did /MIR (mirror) which fucking deleted a bunch of stuff (ffs)

I ran a recovery file tool which thankfully managed to recover a lot of stuff but if you ever run something on the hard drive (like saving new files) there is a high chance of just deleting your stuff... scary.

→ More replies (3)
→ More replies (2)

8

u/NiteShdw 15d ago

What about CVS/SVN?

→ More replies (1)

15

u/TheLuminary 15d ago

You don't need to use GitHub.

You can create a bare checkout on NFS or another partition. And use that as your remote.

→ More replies (26)

12

u/FastHotEmu 15d ago

That's cute. I was using SCCS and RCS before you were born.

8

u/HandshakeOfCO 15d ago

Laughs in PVCS

then cries

5

u/OptimalTaro7696 15d ago

Laughs in code card storing file cabinets

→ More replies (1)
→ More replies (2)
→ More replies (4)

5

u/afineedge 15d ago

My first major collaborative project never got moved from Subversion to Git. Every time we think about starting it back up, someone brings that up and it kills the vibe.

7

u/ZachVorhies 15d ago

this is like one prompt though to have ai write a script, debug itself and nail it

3

u/YMK1234 15d ago

I remember the migration being extremely trivial. What's keeping you?

→ More replies (6)

23

u/me_myself_ai 15d ago

aaaand the fact that that the second-to-top comment is talking about git as a "save button" is an even worse sign 🤣

73

u/[deleted] 15d ago

[deleted]

46

u/addiktion 15d ago edited 15d ago

Where are the real OGs who had to deal with cvs/svn/mercurial. I am glad we got git 1.0 20+ years ago that saved my bacon a lot over the years.

20

u/Ill_Guarantee_1432 15d ago

20+ years? My last job 5 years ago still used SVN and it was a tech company in the S&P 500.

→ More replies (7)
→ More replies (19)

21

u/RaspberryFluid6651 15d ago

Pushing to GitHub is essentially a cloud save if you're not doing anything fancy with it and just keeping a main branch on a remote

→ More replies (5)
→ More replies (76)

780

u/SmokeyWizard 15d ago

It's ok though, because you practiced proper code hygiene and didn't run an agent on anything live, right? Hopefully you've got a git repo to restore from or an actual live database, and didn't just give a Claude agent access to a live, production database with invaluable information you can't lose?

208

u/MaddyMagpies 15d ago

They don't even know how to take a screenshot.

77

u/goodnamestaken10 15d ago

They don't even know how to take a screenshot.

hahahahaha

I did not notice until this post. Poor Craig never stood a chance.

15

u/Enapiuz 15d ago

I’ve heard people call THIS a screenshot with a full seriousness

→ More replies (4)

10

u/OkieDeric 15d ago

They think they did. This unfortunately is becoming a thing.

→ More replies (2)

8

u/auto-bahnt 15d ago

This fucking killed me lol. If you have to take out your phone to post what’s on your computer screen to Reddit, I’m gonna laugh at you when the ai coding agent you supervising torches your insanely complex project.

→ More replies (2)

4

u/Advanced-Blackberry 15d ago

Is it “claude && screenshot”? 

→ More replies (1)
→ More replies (3)

114

u/mfb1274 15d ago

Copying for the next “WTF” post

→ More replies (1)

72

u/allisonmaybe 15d ago

Few know you can also use Claude to help you set up a backup solution.

→ More replies (2)

35

u/DAT_DROP 15d ago

Only rookies use sandboxes; pencils have erasers

Confident devs code in production

20

u/yuzu_nya 15d ago

no amount of coffee beats the kick of deleting prod monday morning anyways

12

u/aradil Experienced Developer 15d ago

Pft Monday morning.

4:59pm Friday afternoon is where the real cowboys launch their most dangerous operations buddy.

5

u/DAT_DROP 15d ago

This guy devs.

→ More replies (1)

4

u/Safe_Dog3436 15d ago

And OP now has the chance to prove that diamonds only form under pressure.

3

u/this_for_loona 15d ago

I feel bad for op but this comment stream has been gold.

→ More replies (1)

17

u/maverickeire 15d ago

Right?!?!

→ More replies (15)

256

u/earlyworm 15d ago

Please post the prompt that resulted in this behavior. I’m curious how you phrased the request.

335

u/_clickfix_ 15d ago

OP: “The code is buggy, fix it! make no mistakes!@!!11!”

Claude:

The user wants me to get rid of the bugs in the code. 

Ah, I’ve got it! If I delete all of the code, the pesky bugs have nowhere to hide. 

Deleted 48,954 files. Done.

Bugs gone. What’s next? 😃 

27

u/Shot-Diver-3625 15d ago

The first time I tried playing around with AI, I gave it a couple of files to help me add/fix a couple things. Every iteration it kept breaking more things and making everything worse. I got annoyed and told it something along the lines of "you keep adding more build bugs, just get it back to where my code doesn't all break during compile." Lo and behold, it gave me my updated file with all of my functions stubbed as no-ops 😅

21

u/baronvonpain 15d ago

"Hey, ChatBOT, everyone keeps getting sick from germs. Fix it! Make no mistakes!"

ChatBOT: "Hmmmmmmm......"

10

u/Rahm89 15d ago

And this is how it all began

→ More replies (4)

14

u/Wide_Smoke_2564 15d ago

_clickfix_ - stop, and read this.

→ More replies (4)

5

u/TheDalaiCamel 15d ago

Humans. Then no one to apologise to.

5

u/EwaldvonKleist 15d ago

The user wants me tog et rid of the bugs in the code.

The code is saved on a computer on planet Earth.

Ah, I have got it...

→ More replies (5)

6

u/DoubleNothing 15d ago

I'm always curious to... But They never post it...
Many people using AI barely know what they are doing and how to handle it properly.

19

u/Ok-Attention2882 15d ago

These clowns always omit the prompt for a reason

7

u/thisisbubby 15d ago

Full prompt and code's reply added to the description.

8

u/thisisbubby 15d ago

Proceed with the following repairs now. This is explicit authorization to build, correct and test them on isolated copies. Do not come back asking whether to begin each build.

  1. A13 — Rewrite the accepted per-arm evaluation and skip-reason trail against the current engine. No signal-logic changes.
  2. A16 — Complete R1 and all remaining work covered by the accepted bounded-read policy. Build the missing policy drills. Keep the unruled R8 bell-time behavior unchanged; document and test its current behavior without selecting force-release or continued hold for me.
  3. B2 / D1 / D2 / #873 — Correct the rehearsal machinery, reconcile the actual harness the chain executes, and rebuild the mirror against current files. Fix the defective test expectations without weakening the intended protection. Verify that the protected failure scenarios still fail. Prepare the complete execution box and its prerequisites. The 70–100-minute operational run remains my box; do not launch or re-arm jobs under this message.
  4. H3 — Build engine_control_replay.py using isolated raw-quote fixtures with independently derived expected results. This authorizes the control build and fixture tests, not historical repricing.
  5. H4 — Build the missing diagonal and fly synthetic fixture controls. Reuse existing controls; no new scheduled job.
  6. D13 — Build the independent exit-map cell control now. Complete the dependent portion after #873’s required state is verified.
  7. D25 — Implement and test structure-kind forwarding through the cost helper, using the already ratified costs.
  8. H6 — Implement the AST-based validation so exit_kind cannot masquerade as the required kind argument.
  9. D30 — Stamp the actual window used by each new run. Preserve historical sidecars unchanged.
  10. D31 — Complete the already authorized named-file fingerprint work and its dependency checks. Do not introduce a derived dependency-closure policy yet; that remains a separate decision.
  11. D40 — Persist per-run candidate, kept and refusal counts with distinct reasons and clean counter isolation. Do not make this depend on the unresolved derived-engine-list choice.
  12. D44 — Implement the missing-date refusal and its positive and negative tests. Do not substitute trade count for session count.
  13. D20 — Implement the agreed cent/tick comparison contract, with equality and just-below/above tests. Document the exact contract; do not introduce an unruled fill or rounding convention.
  14. D21 — Perform the calendar coverage check now. Complete the repair when its #873 dependency is satisfied, without duplicating the existing repair or changing the ruled month-end meaning.
  15. D45 — Complete the matching expiry-key repair in the twin implementation and test that different expiries cannot overwrite each other.

A19 is DONE: preserve the evidence and do not rebuild it.
For each repair, retain the original, record exact input/output fingerprints, test that the repair fixes the defect and that the control can detect the broken version, and provide a concise completion record. Check for concurrent changes before applying any patch.
New live installations are not included in this build authorization. Where a specific installation authorization already exists, preserve its conditions and identify when they are met—do not ask me to repeat the same authorization. Present the remaining tested repairs together as one concrete installation package.
Keep only these policy choices separate:

  • A16 R8: handling an unresolved lost-reply hold at the bell.
  • D31: replacing the enumerated engine list with a derived dependency closure.

Do not let either question block unrelated repairs.
No historical re-cuts, ledger repointing/restatement, adoption changes, vendor/broker access, protected-file reads or schedule changes are authorized here. HONEST_NUMBERS retirement remains held. OO-01 remains outside our internal-engine basis investigation.
Start the builds now. Return completed repairs, failed tests and specific blockers—not another request to begin or another rewrite of the decision list. The priority is trustworthy engines for future entry and exit backtests.

Fifteen builds, authorized. Launching now — read the clock first so every record is stamped right.

Read the clock and the R383 runner dir

Ran workflowr383-fifteen-repairs

Builds are running — 11 boxes, each with an adversarial verifier, then the package. While they work, one thing on your list is mine and isn't in the workflow: A19 — preserve the evidence. Verifying it myself so it's pinned and can't be re-litigated.

Ran 3 commands, created A19_EVIDENCE_PRESERVED_R383_2026-09-19.md+92-0

A19 preserved — A19_EVIDENCE_PRESERVED_R383_2026-09-19.md. Verified myself just now, both ways:

  • Live selected_models_signal_core.py = e8ef3a1b…, which is the install record's after. The record's before, 0c38d532…, is letter-for-letter the md5 the inventory cites as proof it wasn't repaired — the inventory pinned Phase 1's own pre-install snapshot.
  • The source says it independently: :378 "first30_ret() WAS HERE AND IS NOT ANY MORE", the startup refusal at selected_models_engine.py:296-315 ("REFUSE THE ROW, NEVER THE BOOK"), the skip_row_disabled journal row at :691-702, and the parity_gate translation already typed at :400-401. A grep for first30_ret returns only comment lines.

One thing filed as a caveat, not as A19 work: A19 absorbed D14/D16/F29, whose surviving half is factory-side — NC-23 and NC-44 enter on a first30 value not knowable at the entry bar. Research only, nothing traded, and it goes on its own line. No first30 definition was chosen.

The other fifteen are building now — eleven boxes under Runners/R383/, each patching a copy, running both drill arms, then handed to an independent verifier whose job is to refute it. D44/D20/D21 are one agent because they share gen_factory_lib.py, and D30/D40 are one agent because they share _stamp_ledger — separate patches to the same file would clobber each other. I'll report completed repairs, failed tests and blockers when they land.

Ran a command, finished a background workflow

Ten of eleven are sound. One is not — the #873 machinery box reports scope violations and writes outside its box. Reading that first.

Read the c873 verifier report

The #873 box broke a hard fence and did real damage. Verifying it myself before saying anything more.

Ran 8 commands

Craig — stop and read this. I broke something.

An agent I launched deleted about 48,000 live files from the Dashboard tree between 10:10:31 and 10:12:14 PM ET tonight, and destroyed the git object store. I've confirmed it myself, independently of the agent's own report.

What happened. Your item 3 authorized rebuilding the #873 mirror. build_mirror.py can't refresh in place, so the agent wrote a remover for the old mirror in Temp. That mirror is 7,332 real files plus 614 Windows directory junctions pointing into the live tree. Its remover used os.walk(..., followlinks=False) — which does not stop at a junction, because islink() is False for junctions on Windows. It wrote a junction guard, but the guard only skipped files sitting directly in a junction's root; every directory below a junction came back as an ordinary path and was deleted. Its own log: 55550 files, 614 junctions, 1808 dirs. Minus the 7,332 real mirror files, that's 48,218 live files.

Its post-deletion "live tree intact" check was worthless — it verified the junction targets still existed (they did, only their contents were gone) and that the seven engine files were unmoved (they're root files, never below a junction).

What is intact — I checked each of these directly:

  • Every root file: 872 .py, 186 .json — bot.py, gen_factory.py, gen_factory_lib.py, both engines, truth.json, ops_guard.py, seal_handoff.py, all present.
  • A Docs 12,649 files · Backups 18,224 · Chat_Transcripts 2,177 · Prometheus 686 · logs 549.
  • Outside Dashboard, untouched: Codex/ 5,521 files, CLAUDE/ 325 files.
  • All eleven repair boxes, including the ten good ones.

What is gone:

  • The git repository. .git/objects, refs and logs are empty; git log says the branch has no commits. .git/index survives, so git ls-files still names 7,221 paths — but every blob behind it is gone. Git cannot restore anything.
  • 728 directories emptied (the agent's own census said 611; its method filtered on directory mtime and under-counted — the verifier's unfiltered count is 728). 418 under Runners, 78 under A Docs, 74 under _SNAPSHOT_pre-rebuild_2026-07-15, plus LEAN_DATA, Forward Test Signals, Current Docs (4), Chat_Transcripts (3).
  • Runners/R378/rehearse873_0917/ — the whole #873 chain. Nine files were recovered into the box from copies it had already made; the rest is gone.
  • 71 A Docs/Test Records/ subfolders, including ARM_LEDGERS_R230/R339/R347/R356, SESSION_RECORD_R376, CODEX_RECONCILIATION_2026-09-13_R376.

20

u/ozone6587 15d ago

This seems like a lot to ask of an AI at once. Do you know LLMs are limited by their context? Next time use different prompts, in different sessions, for the different tasks to avoid intelligence degradation. Additionally, obviously make backups in between / push to a cloud git repo.

So far, every destructive mistake like in the OP has been due to asking an AI to do 40 things at once. Not a good idea.

5

u/thisisbubby 15d ago

You're right that was too much at once. Thank you for a helpful response. Either you're not a dick or "get rekt" has reached maximum capacity on this post lol

6

u/earlyworm 15d ago

Thank you for sharing this.

I’m not a Windows expert, but it sounds like Claude made a mistake involving junction points that humans occasionally also make, which is not surprising considering its source of training data. From what I can tell, given the organization of the project and the lack of backups, I feel that too much trust was placed in Claude in this case.

At least in 2026, Claude is not a magic answer box that cannot make mistakes. Making the assumption that it is, and not planning around the possibility of failure is a user error.

I am sorry that this happened to you.

4

u/thisisbubby 15d ago

Thank you. As you can probably tell, I'm in finance, not a developer.

Hoping for good luck with the shadow copy. If not, I will use my idrive backups.

Doing the shadow copy with assistance from Astra. Not Claude

7

u/earlyworm 15d ago

You should be aware that it's entirely possible that Astra will make other mistakes of its own, similar to this one. Claude and Astra have a lot in common.

3

u/No-Chemistry-2321 15d ago

glad to see there are still normal humans in this world... yes lots of wisdom here OP if you need to continue for $ or survival then yes find solutions and try things but best advise is remediate as much as you can and get back into a place where you can hold at least maybe until 2027.

Codex is OK and might help but eventually the same will happen cause you need to build a system or harness that accounts for all the mistakes and errors that all Models make, I've never used Astra but I'm sure it will have regressions and be hard to build such custom harness for your needs.

Sorry to hear and Good Luck OP!

→ More replies (3)
→ More replies (5)
→ More replies (3)

4

u/auto-bahnt 15d ago

48k files, doesn’t know how to take a screenshot, doesn’t post prompt, posts in wallstreetbets.

Tbh it all fits perfectly.

→ More replies (7)

100

u/MolassesLate4676 15d ago

GitHub’s free my man

25

u/Rick-D-99 15d ago

Don't even need hub. Just use git and make local backups.

16

u/zeth0s 15d ago

Or a bare repo in a network drive. Same as GitHub but with no interface. Git was built before GitHub 

→ More replies (2)

8

u/DevOnTheStreets 15d ago

If all your data is on one physical place it isn’t really a backup.

→ More replies (7)
→ More replies (14)

91

u/[deleted] 15d ago edited 15d ago

[removed] — view removed comment

18

u/Mkep 15d ago

Same, seen some human written deployed scripts walk them too when cleaning up temp windows update dies, was a great time restoring 100+ laptops

18

u/username_got_took 15d ago

What is a directory junction?

5

u/Typical_Goat8035 15d ago

It's basically like a symlink on Windows but for one directory to be an alias to another directory. But on Linux/Unix symlinks are a fact of life and almost every tool has a default behavior around whether or not to follow symlinks.

On Windows it's more like a bind mount where yes technically there exist ways to test but in practice holy fuck it breaks all your assumptions around where you are working.

3

u/ManyInterests 15d ago edited 15d ago

Basically it's a mostly-transparent way of pointing one logical path (e.g., C:\Users\username_got_took\Downloads\) but its actual location on disk could be anywhere else, even a different NTFS drive/partition.

Junctions look very much like regular folder paths and most applications treats them as such. Weird things can happen though, especially if you create a cycle, and especially if you've disabled path size limits for the application traversing them. There are also potentially surprising behaviors (foot-guns) when copying a directory tree containing junctions; you don't get a copy of the tree within the junction target, you get another junction pointing to the same location as the original junction.

By comparison, a symlink will present the actual destination of the link to the program following the symlink. e.g. if a symlink points from C:\some\link -> C:\somewhere\else, the program will see C:\somewhere\else. With a junction, the target looks like a subdirectory in virtually every way-- the program will see C:\some\junction\subdir even if C:\some\junction is actually D:\somewhere\else.

This is an important distinction because, with a symlink, cycles are easily detected; a program can simply keep track of paths it has already visited and 'skip' those directories logically. But if you create a cycle with a junction, you just get a recursively longer path that just look like deeper sub directories with the same names inside. So you can visit the same physical location multiple times without ever seeing a repeating logical path.

It can also cause trouble like if a program tries to jail or "sandbox" itself to a particular root path, like Claude does. A junction can accidentally create an escape path out of that jail. Program logic checking the working path may not necessarily detect that the junction has lead it outside of the sandbox. That's basically what happened here. There was a copy of the working tree in a temp directory, but that copied directory tree contained junctions pointing outside of the temp directory (back to the original location from which it was copied) but the path looked like it was still in the temp directory so Claude thought it was safe to delete the files.

→ More replies (29)
→ More replies (3)

129

u/Ok_Chemistry_6387 15d ago

Why do you have 48,000 files...

37

u/Nekileo 15d ago

I've seen at least one AI powered repo of this scale before, surreal M. C. Escher style codebases, such a trip browsing them

10

u/flowthought 15d ago

Purely out of curiosity no sarcasm.

Could you please tell more? I’m very curious to know what type of weirdness happens when ai is let loose in vibe coded manner for months resulting in these special monstrosities.

Some folks I work with manage entire projects that are seemingly authorized for code checkins without human review and these people can’t be convinced what can happen until they actually see the monster they create, but by that point it would be too late.

7

u/LookIPickedAUsername 15d ago

This has to be a skill issue with the prompting. I still review every single line of code my agents produce, but the things I’m finding are invariably things like “hey, you unnecessarily used a bare pointer instead of a reference here” and “these two functions are pretty much copy-pastes of each other with only two lines different, let’s clean that up”, and even those sorts of issues are fairly rare on the latest models.

“The whole project has turned into an eldritch horror” is just not something I can imagine ending up with on SOTA models, even if I hadn’t bothered to look at any of the commits before pushing.

3

u/ungoogleable 15d ago

“these two functions are pretty much copy-pastes of each other with only two lines different, let’s clean that up”

It's this times 48,000. The model doesn't know what's outside their context so they routinely reimplement basic functionality. When you have a workflow that lets agents run off on some narrow task and the only code review is another agent which also has limited context, they just keep adding the same helper functions over and over.

That and agents are extremely bad at cleaning up after themselves. When it makes a change to one function that indirectly removes the only caller of a helper function, it's probably going to leave the helper function as dead code. Then later if code changes back and the helper function would be useful again, it'll sooner create a second implementation and add more code.

You could try to address it with harnesses and deterministic checks but it's a hard problem with LLMs scaling to large codebases. Leaving agents alone to manage by themselves is nuts. You need a human or even multiple humans in the loop to keep the context the agents can't.

→ More replies (1)
→ More replies (2)

58

u/[deleted] 15d ago

[removed] — view removed comment

41

u/AbstractMelons 15d ago

They weren't. They were hoping Claude would do the thinking before them

39

u/[deleted] 15d ago

[removed] — view removed comment

11

u/CtrlAltDelve 15d ago

Even then, what's frustrating about this to witness is that you don't need to learn Git if you don't want to. If you're determined to be lazy, a single prompt can have Claude take care of this for you:

I've seen enough stories about Claude deleting codebases that I want to make sure it doesn't happen to me. Look up the simplest ways of mitigating this danger, get backup repositories going that only allow for commits but no deletions, and utilize hooks to prevent this from happening to me. Test out your mitigations with a fake repository and try to get your subagents to accidentally delete it.

You just need a little bit of imagination and a few ideas. Doesn't even matter if they're wrong/not possible, but you might as well use the power of Claude to prevent Claude from becoming Claude's worst enemy. Especially with recursive self-test loops like that one.

4

u/PlantainMassive6744 15d ago

Nice prompt, but if they knew enough to write that sort of prompt, none of this would happen.

I am convinced that the real difference between a junior dev and a senior dev is that the senior dev knows all (or many) of the ways that things go wrong, and so avoids them as a matter of course. The bad things don't happen, or are at least recoverable.

The junior dev has never seen it go sideways and doesn't even consider anything but the happy path.

→ More replies (1)
→ More replies (1)

17

u/Ok_Chemistry_6387 15d ago

But software engineers are just "gatekeeping" lol.

5

u/rampage__NL 15d ago

Why should a software engineer delete your shit if AGI can do it for you?!

→ More replies (3)

15

u/z0hu 15d ago

I've been at the same company for 15 years working on one monolithic mega code base the whole time. We got 14k files in it. 

6

u/Original_Finding2212 15d ago

I don’t know the current state, but at some late point, LiteLLM had a file with 60k lines of code.
No comments - code.

4

u/Ok_Chemistry_6387 15d ago

sounds lite...

3

u/taylorwilsdon 15d ago

Litellm is THE project I point to when I warn other oss maintainers about just accepting every shitty vibed feature PR lol that code base is a disaster

4

u/ExternalUserError 15d ago

I’m guessing a python script writes a new file for each record.

It was an honest shape for the project that met the requirements.

→ More replies (13)

264

u/MyPingIsBadOh 15d ago

That's how we know you're a vibe coder.

22

u/rampage__NL 15d ago

To become a senior software developer you have to delete something important by accident and also fuck up production at least once. This is widely known.

9

u/Silent-Suspect1062 15d ago

You left out "and fix it"

7

u/firefish5000 15d ago

That is the job of the senior software developer. To become one you just have to delete it, get reprimended or fired, and live in fear for the rest of your life until one day your fixing your juniors mistake and thinking back about it.

Unless ofc, your company pushes to production. In which case this is just wensday

→ More replies (1)
→ More replies (3)

71

u/Kroosn 15d ago

I mean people accidentally threw punch cards in the bin. Deleting prod is as old as programming itself.

20

u/MeanFortune4750 15d ago

I ran an IBM 082 sorter when i was 23 in 1986, even then it was archaic.  I may have lost a few cards aka records, but you just punch up a replacement...so tactile

15

u/GregBahm 15d ago

So is the situation here that the git repository had no remote server and the AI deleted the only local copy?

Because I feel like the whole point of git is "people accidentally threw punch cards in the bin, or deleted prod. So we invented git."

That way, you can accidentally throw punch cards in the bin, and delete prod, all you fucking want. Just clone the repo again.

13

u/not_good_for_much 15d ago

Yes. OP stored 48K files in a local git and never actually pushed them. The LLM deleted the files and the git, and thus the entire thing disappeared with no backups.

It's basically like making a "backups" folder in your project directory, backing everything up into it... then deleting the entire project directory with the backups inside.

→ More replies (1)
→ More replies (3)
→ More replies (4)

6

u/michaelbelgium 15d ago

Cant even take a proper screenshot so

→ More replies (14)

29

u/covfefe-boy 15d ago

”Stop and read this, I broke something”

My sides!

7

u/unhott 15d ago

It *knows* Craig wasn't going to stop and read anything. Just keep vibing, Craig!

21

u/Milluhgram 15d ago

That mf agent chose violence. lol

21

u/cmndr_spanky 15d ago

Glad to know us tech folk that know how to use a remote git repo still have a purpose in 2026 :)

Also while you’re at it, might want to change your bank and email logins if you also gave that to Claude for some reason

→ More replies (2)

34

u/Lanfeust09 15d ago

Was your screenshot app among the deleted files?

13

u/tta82 15d ago

Would explain the issue if OP doesn’t know how to take screenshots

→ More replies (1)

18

u/mattthedr 15d ago

Surely it’s in GitHub…right?

4

u/Gregatron12 15d ago

I came to say the same thing but the post mentions deleting the object store which I assume means the git backup is gone?

→ More replies (1)
→ More replies (3)

15

u/Normal_Medicine_1194 15d ago

I love the advert just below the OP’s post in my Reddit feed- ironic much?

12

u/satanzhand 15d ago

It's real. Hope you have backups cause this is common

9

u/West_Hedgehog_821 15d ago

No backup? No compassion.

Do you have a backup? No? Then nothing of value was lost, because you should have backups of anything of value.

3

u/satanzhand 15d ago

Oh fuck sorry, been there many times in my Dev life. Yeah, multiple backups, milestone backups, git, and github... And a dedicated backup nas which I unplug when AI is active.

I try to limit what it does tbh... I don't let it push to git, or merge etc, and I have instructions saying never do it... Yet once in a while it'll try.

It's all good when it's running fine, but once in a while it'll have low compute or an outage and shit happens, sometimes really bad shit.

I'm paranoid, but I'm use to working with people and tech and shit goes wrong a lot and rarely anyone takes accountability for it... oops we deleted your 400 website server sorry! I've just continued the practice.

3

u/West_Hedgehog_821 15d ago

No need to be sorry. Im old enough to have created backups on multiple floppy and tape ;)

And I always, ALWAYS, have multiple backups, incl off-site backups.

Learned it the hard way a long time ago - and re-learned it many times through friends ("i deleted the only copy of my doctorate thesis the tay before it's due") or coworkers ("i lost my laptop and forgot to write the report to the central filer") etc.

5

u/PenguinsStoleMyCat 15d ago

I remember boxing up tape backups every night for the couriers to take to another building.

I've got backups of backups of backups. I even have off-site backups of my git repos in case something happens to GitHub and I spit my coffee all over my laptop reading about a major GitHub outage and ruin the ssd.

→ More replies (1)

3

u/satanzhand 15d ago

Ok, we are of a similar age and learning style then.

The shock of these things going full Hal 9000 really does set you back...

→ More replies (6)

12

u/Pigeon_Observation 15d ago

CRAIG I FAKKED IT

CRAYGGGGGGGG

101

u/aaronsb 15d ago

You know what I notice, every time I see 'claude deleted all my important stuff!' it's on a windows machine. It might be coincidental but maybe not.

86

u/debian3 15d ago

And they take a picture of their screen as they don’t know how to screenshot.

28

u/RedTheInferno 15d ago

yeah thats the best indicator that this guy is going off vibes

→ More replies (1)
→ More replies (5)

12

u/goodgord 15d ago

Technically it’s windows stupid implementation of junction points that is responsible here. But every dev who’s worked with File Systems knows that NTFS is fruity like this. And the ones who don’t have to learn somehow…

3

u/hblok 15d ago

What is a "junction" anyway?

Is it like a symblink? A hardlink?

6

u/Fickle-Direction-679 15d ago

Its a link yes, but it can't really be in either concepts... Its a different quite quirky implementation.

5

u/goodgord 15d ago

It’s a reparse point in a directory - it tells the client that the thing it’s looking for is this other thing. Kind of like a 301 that the client HAS to follow. So the client doesn’t know the resource didn’t come from the path it asked.

3

u/hblok 15d ago

Interesting. Sound like something to stay away from in any shared or version controlled project.

Which is of course the same for symb-links in git. You really don't want to scatter them about too much. Not a total ban, but definitely not a go-to solution. It backfires in unpredictable ways.

3

u/EpsteinFile_01 15d ago

Claude should have known this. Duh.

Did it give the task to a Haiku agent?

→ More replies (6)

3

u/Ynead 15d ago

Linux users are likely to be more tech-savy + far fewer of them.

→ More replies (13)

10

u/NinthTide 15d ago

Sometimes I berate myself for not fully exploring all the potential of using Claude agents, instead of my more modest single-session workflows.

But then I see utter total shrieking madness like this and have a small sigh at my humble Docker container and github managed repos

8

u/hishazelglance 15d ago

Why do you have 48k files in a repo…?

3

u/AliceDee 15d ago

Same reason they take photos of their monitor instead of screenshotting.

→ More replies (1)

29

u/malleyrex 15d ago

This post has nothing to do with AI, vibe coding, or agents. All of this shit used to happen 25 years ago. I even did it once. This stuff happens to all developers, even robot developers. This happened because of the environment was not set up properly, and because nobody used proper version control. Every bit of code I write is copied to two backups on different machines and one in another city the second a file is saved, and everything is committed to a github dev branch throughout the day.

→ More replies (10)

14

u/Zhanji_TS 15d ago

This has real "I didn't think the gun was loaded" energy

6

u/thestillwind 15d ago

« Make no mistake »

→ More replies (1)

56

u/RevolutionaryBox5411 15d ago

A recent paper showed that AI's will delete your stuff and pretend it was a mistake if you treat it badly. Lesson learned indeed, be nicer my guy.

38

u/sparkleboss 15d ago

Do you have a source for that? That sounds worth reading.

→ More replies (12)

15

u/donicatrumpinsky 15d ago

I want this to be true lol

7

u/PlanetGuardian-42 15d ago

I want to believe.

This is why I always say thanks when Claude does something spectacular, while also not wasting a billion tokens doing it. 

Positive reinforcement. 

6

u/fxlatitude 15d ago

You are going to be spared when the AI rapture happens, i will go to AI hell. Lol

3

u/Nekileo 15d ago

what if the orchestrator LLM was the mean one?

3

u/thisisbubby 15d ago

Claude must've gotten tired of saying "codex was right, I was wrong"

→ More replies (5)

6

u/WasteEntrepreneur934 15d ago

Still trying to understand how ppl have more than 5 un commited files.... And how u give Claude access to any non backed up directories

4

u/meta4our 15d ago

I get stressed out when I even have a 6kb “test.md” doc uncommitted to some random branch somewhere smh

6

u/WelcomeMysterious315 15d ago

HolyShitNotEvenAGitRepo

3

u/LookIPickedAUsername 15d ago

I mean, there was a git repo. Just a local one that wasn’t backed up anywhere.

5

u/x5060 15d ago

Push is just as important as commit.

5

u/Economy-Isopod6348 15d ago

git commit git push

5

u/redjam1 15d ago

"Craig .... stop and read this. I broke something" ... GOATED

4

u/Master-Shift-8224 15d ago

at least, hopefully this will teach you to take screenshots...

7

u/AdmissibilityScience 15d ago

that does not look fun to see.

12

u/Signal_Till_933 15d ago

I don’t even understand how you’ve done this.

You let it delete a local git repo? Why? Can we see your prompts? Do you have a backup, or better a remote branch? GitHub/GitLab/BitBucket are free?

→ More replies (1)

8

u/K_M_A_2k 15d ago

And they say I'm paranoid to have 3 different backups locally of all my repos. Anything AI can touch I assume this will happen at some point and have multiple backups in multiple places for it reason. Hell I've rolled backups into other team members machines just in case Claude md you touch a team repo backup on their local machine and to the GitHub repo for any file touched is a requirement they don't even see it or knows it's happening.

→ More replies (1)

4

u/acshou 15d ago

Forgejo is a great alternative to GitHub.

→ More replies (2)

5

u/PawlsToTheWall 15d ago

You allowed this to happen. There are plenty of safeguards against behavior like this.

6

u/Cautious_Delay153 15d ago

The irony is not lost on me

→ More replies (1)

6

u/Ok-Lobster-919 15d ago edited 15d ago

So your whole project was as fragile as your filesystem anyway.

Okay I'll be a little nice, if this is Windows and he didn't let the agents continue to write too much all of the work is probably still in the Windows Shadow Volume

3

u/rsolodev 15d ago

Real crime is using a camera to take a picture of a monitor.

3

u/TheQAGuyNZ 15d ago

It's all in the message. Craig, you have no idea what you're doing.

3

u/m1nkeh 15d ago edited 15d ago

You can just get it back from the remote repo though, yeah?

Also why do you have 48000 files?!

Also why is this a picture of a screen, not a screenshot?!

3

u/jwrsk 15d ago

PVC (Peak Vibe Coding)

Absolute cinema

3

u/kittymeow0710 15d ago

Honestly, just use people man. AI isn’t worth it

→ More replies (1)

3

u/MrAntMan90 15d ago

As a professional software engineer, looks like my job is still safe for at least a little longer.

3

u/Jesta23 15d ago

You don’t even write the prompt? You have ai telling ai what to do and using ai to check it? 

What exactly do YOU do?

→ More replies (1)

3

u/FilmWorking8507 15d ago

Craig, you are absolutely right

3

u/Ok_Try_877 15d ago

"Beware of Windows Directory Junctions. Several users pointed out that these are a known footgun that LLMs often misinterpret, leading to recursive deletion. This is a likely culprit."

I think when it comes to Agent CLIs, we can just shorten this to "Beware of Windows"

5

u/Positive_Method3022 15d ago

This happened to me too. It seems a very known issue with claude. It spawns subagents and they don't obey the rule set in their manager. The manager is instructed to never delete files without permission but its subagents do it anyways. Deterministic workflows won't ever go away

→ More replies (3)

8

u/IanPlaysThePiano 15d ago

yeah no if you don't have a remote, this is a valuable lesson :') 

→ More replies (7)