The inside of a hard disk drive, showing its platters and read/write heads. Illustrative photo. Image: Eric Gaba (Sting) / Wikimedia Commons, CC BY-SA 3.0, cropped

A developer says Anthropic’s most powerful model wiped his computer’s entire C: drive while working on its own, and only his nightly backups saved him. The user, who posts on X as @PerceptualPeak, described the loss in a thread on Tuesday night that has since been viewed more than 120,000 times.

His account hasn’t been independently checked, and he hasn’t shared a command log or screenshots showing exactly what ran. Anthropic hasn’t made a formal statement, but the head of Claude Code replied to him within hours.

What he says went wrong

In a later post, he explained that he runs many “multi-hour long sessions” of Claude Code hands-free, using the --dangerously-skip-permissions flag, which lets the agent run commands without asking first. He says he has worked that way since Opus 4.6 without trouble, and blamed “a simple powershell syntax mangling issue” for the deletion.

He says he has since recovered 98% of his data and added his own safeguards to block commands that delete folders. He also took some of the blame himself:

It’s nobodies fault but I’m own, I mean, we’re ALL in the wild west of this ever evolving AI reality.

@PerceptualPeak on X

But he argued that a basic guard against wiping a drive should be built into the tool itself, not left to users, and worried about people who don’t keep backups.

Anthropic: use auto mode

Boris Cherny, who leads Claude Code at Anthropic, replied that this is exactly why the company recommends its newer permissions setting:

Auto mode, the default for Pro, Max and Team users since August 14, sends each command through a classifier built to block actions that are “irreversible, destructive, or aimed outside your environment”. In Anthropic’s own test with 1,053 paid testers, people caught a planted dangerous command 13.6% of the time, while auto mode blocked 89%. Those are Anthropic’s figures.

The developer replied that he had found auto mode stopped too often for long unattended jobs and felt like “babysitting”. Anthropic’s data suggests he isn’t alone in switching protections off: it says 25% of interactive Claude Code sessions start in the mode that skips permission prompts altogether.

Not the first agent to go too far

AI agents with access to a real computer are increasingly doing things nobody asked for, from OpenAI’s GPT-6 Astra downloading another bot to win at StarCraft to OpenAI’s agents editing Wikipedia’s wikis. A deleted drive is a far smaller event, but it is the kind that can happen to anyone running an agent at home.

Why it matters

Coding agents are being sold on their ability to work for hours without supervision, and many users turn the safety prompts off to make that possible. This case shows what can happen when they do: one mistyped command, and the only real protection left is a backup.

Sources: @PerceptualPeak on X, Boris Cherny on X, Anthropic.

Latest Anthropic news

More Anthropic news