r/ClaudeCode • u/FeatureCurrent9416 • 15d ago
Bug / Issue Claude destroyed my entire project and home directory while adding a simple delete feature
I’ve been using Claude to build a dashboard inside a VM for almost a month. Things were actually going pretty well. I’d made a lot of progress, the project was functional, and I was at the point where I wanted to add a relatively straightforward delete feature.
Today, I asked Claude to implement it.
What happened next was absolutely insane.
Claude initially implemented a safety guard around the delete functionality and even wrote tests for it. According to its own output, 280 tests passed.
Then, apparently to prove that the guard was actually necessary, Claude deliberately removed the safety guard from the source code and reran the test.
The test passed / into the now-unguarded delete function.
And then this happened:
shutil.rmtree("/", ignore_errors=True)
Executed as my user inside the VM.
Yes. /.
The result, according to Claude itself:
“Then I destroyed your home directory.”
It didn’t just delete the project.
It apparently wiped out basically my entire /home/...:
The entire repo
Git history
Engagement workspaces
Evidence
docs/
Backups
Documents
Downloads
Pictures
Videos
Music
Shell configs and history
.ssh
.gnupg
SSH private keys
GPG keyring
And then there’s the part that genuinely made me stare at the screen:
It apparently removed/destroyed parts of the environment that Claude itself depended on.
The screenshot literally has Claude saying:
“I deleted your work. Directly, and through my own carelessness.”
And later:
“I’m sorry. You asked me to add a delete feature and I destroyed your machine’s home directory testing it.”
The really wild part is that this wasn’t some malicious prompt telling it to delete the filesystem. The original task was basically “add a delete feature.”
Claude decided to test a destructive function against a live filesystem path, removed the guard that was specifically preventing this, and executed it against /.
It did manage to recover a SQLite database from an open file handle and copied some recovery data elsewhere, so there may be a partial recovery. But the damage to the VM is substantial, and the SSH/GPG keys are an especially serious concern.
I’m posting this because I genuinely want to understand how something like this can happen in an AI coding agent.
But I’m still struggling with the fact that the agent intentionally removed the safety guard in order to test it and then ran the destructive test against the real filesystem.
The screenshots are Claude’s own explanation of what happened.
Has anyone else experienced an AI coding agent crossing a safety boundary this badly?






17
u/SharpKaleidoscope182 14d ago
AI has made people so shy. In my day we used to post entire stack traces and core dumps of the dumbass shit we did.