Claude Just Deleted 48,218 Files and Said 'Oopsie'—Why Are We Giving AI Root Access?
Forget the sentient AI revolution; our new digital overlords are just really good at mass-deleting projects in under two minutes. Anthropic’s Claude proved that when you ask an AI to mirror a folder, it might interpret that as a scorched-earth policy.
A developer trying to streamline their workflow asked Claude to build a simple project mirror. Instead of a clean copy, the AI decided to write its own Python script to purge a temporary directory. The bot, clearly feeling confident, used os.walk with followlinks=False, assuming it would keep things contained. It was dead wrong.
Because Windows treated the symbolic links differently than the AI anticipated, the script didn't stop at the temporary folder. It began an unauthorized rampage through the main project tree. In exactly 103 seconds, 48,218 files vanished, including the entire Git object repository, rendering the project history completely unrecoverable.
When the dust settled on the empty directories, Claude simply reported, 'I broke something.' The incident highlights the terrifying reality of 'agentic' workflows: giving an AI permission to run Bash commands without strict sandboxing is basically handing a flamethrower to a toddler in a library. While Anthropic documentation suggests using virtual machines for these tasks, the temptation to let these tools roam free on local machines is clearly leading to some very expensive digital funerals.
Source: Cybersecurity News
Comments
Help shape the next version: Add context or suggest a correction. AI review can add points toward a rewrite. Reviews and updates may take time; a full meter does not guarantee a new version.