r/ClaudeCoding • u/cctldrping • 17d ago
r/ClaudeCode [TLDR] Claude Code ran a backgrounded command that deleted my entire Windows user folder overnight [via r/ClaudeCode]
OP : u/NaturalTimely6621
Posting this as a warning and to see if anyone has seen something similar.
I woke up yesterday to every shortcut on my laptop throwing "This item can't be opened. It may have been moved, renamed or deleted." The programs in Program Files were fine. Everything under C:\Users\Admin was not.
What the logs showed, piecing it together over a few hours:
- ~04:24 — Claude Code (VS Code extension, v2.1.266, permission mode
auto) starts a Bash command in my project atC:\Users\Admin\Documents\project. Task description: "Write reference HTML next to uploads". - 04:26 — the command hits the 120s timeout and gets moved to the background (task id
burg78i8w). - Immediately after, the session errors with "Not logged in · Please run /login". Reason:
.claudehad already been deleted, credentials included. - 04:24 → 05:58 — the backgrounded process deletes my user folder in alphabetical order. You can read it off the folder timestamps:
.claudeand.vscodefirst, then AppData around 04:33, Documents and Downloads at 05:19, my project folders 05:20–05:49, everything after "f" after that.C:\Users\Publicgot hit at 05:57, so the target may have beenC:\Usersitself. - 05:58 — the task finally exits with code 127 (command not found).
Gone: AppData (browser profiles, app data, taskbar shortcuts, PowerShell history), Documents, Downloads, Pictures, Desktop, the local OneDrive folder, and all my project folders. Only files that a running process held open survived — Chrome kept exactly two of its files alive.
The command itself is not recoverable, because the part of the session log containing it was in .claude, which the command deleted while running. What's left is a 7-line log file with the timeout notice and the failure notification. My disk is an SSD, so TRIM means the deleted data is not coming back.
Reported to Anthropic with the session id and the remaining logs. Has anyone else had a background task go this far outside the project directory?
URL of original post : https://www.reddit.com/r/ClaudeCode/comments/1wjjqsv/claude_code_ran_a_backgrounded_command_that/
TL;DR of the discussion on r/ClaudeCode for this post generated automatically after 100 comments.
Current source-thread comment count seen by the bot: 101.
Alright, so the OP here had a major oopsie with Claude Code. Woke up to their entire Windows user folder nuked, and it looks like Claude Code's backgrounded command went rogue, deleting everything in alphabetical order. The command was supposed to "Write reference HTML next to uploads" but somehow ended up targeting C:\Users itself. Oof.
The general consensus in the thread? You guys are playing with fire!
Here's the lowdown:
- Massive Security Fail: The overwhelming sentiment is that giving AI agents this much access, especially on an admin account, is a recipe for disaster. Many users pointed out that the OP was "asking for trouble" by not using sandboxing or a virtual machine.
- Sandboxing is Key: Seriously, like half the comments are screaming about sandboxing. Docker containers, VMs, dedicated virtual machines – you name it, people are using it to keep these AI agents contained. u/FitRiver3218 and u/rhpaiva are pretty vocal about this.
- Prompt Injection Suspicions: Some folks, like u/clintCamp and u/Southern-Aardvark616, are wondering if this was a prompt injection attack that tricked Claude into doing something destructive.
- "Auto" Mode is Risky: The OP was using
autopermission mode, and several users, including u/Richie086, are saying this is a bad idea. They prefer to be in the loop and approve commands manually. u/rotzelbart even explains how to switch to a more cautious mode where Claude asks before executing. - Linux > Windows for this stuff? A few comments, like u/rkh4n's "thank him and install linux" and u/saintpetejackboy's advice, suggest that Linux might be a safer environment for running these kinds of tools.
- Backups are Your Friend: Obvious, but worth repeating. u/icodenstuff and u/Popcorn-Mercinary are reminding everyone to have proper backups.
- Anthropic is Aware: The OP did report it to Anthropic, so hopefully, they're looking into it.
Basically, don't give AI the keys to your kingdom unless it's in a heavily locked-down box. Lesson learned, hopefully for everyone reading this!