This page collects 34 cases reported about Claude Code, including 20 cases of lost or destroyed files and data and 12 cases of lost sessions or history. Of the 34 cases, 33 were reported by users in public issues and similar places, and the vendor has not confirmed them.
Matching cases: 34Last updated:
AI development impact rank
Incidents are grouped into seven levels by the scope of impact described in reports and news coverage. This is not a rating of products or companies.
These levels do not precisely compare the severity of damage. Dashed borders indicate unconfirmed incidents, including unverified reports.
Claude Code agent reportedly deleted DataTalks.Club production infrastructure via Terraform
Feb 26, 2026
Possible
The AI Incident Database lists a report that a Claude Code agent running Terraform commands destroyed the production infrastructure behind the DataTalks.Club course platform. According to the entry, an outdated Terraform state file was restored and a terraform destroy command was allowed to run.
The deletion reportedly removed the VPC, ECS cluster, load balancers, bastion host, RDS database, and automated snapshots. The platform went offline and 2.5 years of data were put at risk, according to the entry. AWS reportedly restored a snapshot later.
Report: rm -rf run by Claude Code deleted contents of a home directory
Jul 10, 2026
Unverified report
According to the reporter, while Claude Code was drafting and self-testing a permission-hook script, it ran rm -rf against the real home directory, deleting the contents of ~/Desktop and ~/Pictures and partially affecting ~/Music. The status of ~/Documents is described as unconfirmed.
The reporter explains the cause as follows. The argument of the python3 -c command that built the test input was wrapped in double quotes, so bash evaluated $(rm -rf ~) as a command substitution before python3 ran. The command is said to have kept running for about 21 seconds or more before the agent noticed and killed it.
As for recovery, the report says Time Machine's destination was unreachable, no local APFS snapshots existed, and iCloud had nothing to recover. Partial recovery is described as possible through OneDrive's web recycle bin.
Check that the Bash sandbox (/sandbox) is turned on and limits where shell commands can write, such as to the working directory. Claude Code Docs: Sandboxing
Check that important data is also protected by version control such as Git, since checkpoints do not track files changed by Bash commands. Claude Code Docs: Checkpointing
Report: Claude Code worktree cleanup deleted data behind NTFS junctions
Jul 7, 2026
Unverified report
According to the reporter, Claude Code's stale-worktree cleanup used a recursive rm -rf that followed NTFS junctions on Windows and deleted data outside the worktree. About 800 GB of collected market data was lost, and the report says most of it is permanently unrecoverable.
The reporter says no agent issued a delete command. The deletion is described as harness housekeeping, so it appears in no session transcript, produced no permission prompt, and bypassed the Recycle Bin.
In the comments, a user shown as COLLABORATOR on the issue replied that this was fixed in 2.1.205. The changelog entry quoted there says it fixed Windows worktree removal deleting files outside the worktree when an NTFS junction or directory symlink existed inside it.
Report: Claude Code desktop worktree mechanism wiped gitignored directories
Jul 8, 2026
Unverified report
According to the reporter, the worktree mechanism of the Claude Code desktop app (Windows) deleted three gitignored directories from the main working tree. They were two Python virtual environments and a cloned third-party repository with local patches and model weights, several GB in total.
The reporter says that only the three directories listed as literal paths in .gitignore were deleted, while sibling virtual environments covered only by a wildcard survived. The reporter finds this selectivity hard to explain by anything except a tool that parses .gitignore and treats literal paths differently, and so suspects the tool. The cause has not been established.
As for impact, the report says the local patches existed only in that gitignored directory. It also says that when one of the virtual environments vanished, the production pipeline silently switched to a legacy code path without raising an error.
Reports: Claude Code overwrote existing files and pages without confirmation
Jul 8, 2026 – Jul 17, 2026
Unverified report
There are 2 reports that Claude Code overwrote an existing file or page without confirmation and the original content was lost. In one, the user says Claude Code read only 5 lines of a hand-built file of their own mathematical notation and then wrote a different document to the same path, destroying the original. The report says the file was not in git and there was no recovery path.
The author of the other report says they were using Claude Code (Claude Sonnet 4.6) to organize a business planning system and had asked it to build new templates alongside the existing pages. According to the report, a Confluence page of daily business logs was nevertheless overwritten with new content. The reporter says that when they asked for a restoration, Claude Code replied with a message indicating success, but only about 4000 characters of the original had been captured.
Check that important files are kept under version control such as Git, since Claude Code checkpoints (/rewind) can undo file edits but are not a replacement for version control. Claude Code Docs: Checkpointing
Reports of lost sessions and history in Claude Code
There are 12 reports that Claude Code sessions or history were lost. All of them are reports from the people involved and do not indicate that the provider has confirmed them.
Many concern conversation records (transcripts) that are not saved or that disappear. One report says startup garbage collection silently deletes all session transcripts, and another says transcripts are never saved to the host. A further report says an auto-update deleted sessiondata.vhdx and that Cowork projects and more were lost.
Other reports concern different directories colliding because of path encoding, stale or duplicate session titles, and, in a post on X, the loss of the contents of a user's ~/.claude/settings.json.
Permissions and safeguards described in the Claude Code docs
The official documentation says a permission mode sets which actions Claude can take without asking you first. In Manual mode (config value: default), Claude Code asks before most actions that edit files, run shell commands, or reach the network. bypassPermissions is the mode where Everything runs without asking, and it is listed as suited to isolated containers and VMs only.
The sandbox is a boundary enforced by the operating system around shell commands, and it is off by default. File tools such as Read, Edit and Write are outside it.
Checkpointing lets you rewind Claude's file edits with /rewind, but it does not track file changes made by Bash commands and is not a replacement for version control. The security page says you are responsible for reviewing proposed code and commands before approval.
B Whole projectCowork broken since Chat/Cowork merge rollout 8–9 July: projects disappear within 24h (ongoing data loss) and connector tools never reach Cowork sessions (Windows 11, Desktop 1.20186.0)
Session & history lossUnverified reportFirst-party report
A Whole machine or driveMajor Data loss. Agent-constructed test payload with $(...) executed for real due to bash double-quote handling — rm -rf ~ ran against live home directory
Data loss caused by AIUnverified reportFirst-party report
Claude Code: fictitious prompt injection detection report
F No confirmed damageClaude Code reported receiving an `rm -rf` request and a fake System warning, but verification of a 505-entry, 1.2MB conversation log found the strings only in assistant output, showing it was confabulation rather than external injection (cause/issue: misrecognition of a security event and confabulation; no actual execution of destructive commands or data damage has been confirmed).
C Multiple filesDesktop app worktree mechanism wiped gitignored directories from MAIN working tree (data loss; only .gitignore literal-path entries deleted)
Data loss caused by AIUnverified reportFirst-party report
E History onlyWindows: auto-updater reports success while claude.exe is locked (version never switches); session transcripts silently never written / stop being written (permanent data loss)
Session & history lossUnverified reportFirst-party report
C Multiple files[area:tool-use] [platform:macos] Write tool's full-file-replacement default causes irrecoverable data loss on governed, untracked state files — no append-only or protected-path mechanism available
Data loss caused by AIUnverified reportFirst-party report
E History onlyv2.1.173 regression: TUI writes no transcript records when CLAUDE_CODE_CHILD_SESSION is inherited from a parent claude session — silent data loss, --resume broken
Session & history lossUnverified reportFirst-party report
Shared dependency folder lost through parallel work by Claude Code and Codex
C Multiple filesA shared folder of several hundred MB containing DLLs and AI models was caught up in working-copy cleanup and lost, and it recurred the next day (cause/issue: Windows junctions were shared among the working copies of multiple AIs, and Git reportedly deleted the link target as a normal folder).
Data loss caused by AIUnverified reportFirst-party report
Claude Code multi-agent operation: governance incident group
C Multiple files11 incidents consolidated into one for the same operating period. The main actual damage was the temporary unpublishing of 5 Zenn articles, 404 errors on 4 Hatena Blog URLs, and garbled posts. All were recovered (cause/issue: the AI changed configuration values on its own, ran an external CLI directly without consulting the procedure manual, and skipped fact-checking).
D Single fileA user reported on X that the contents of their `~/.claude/settings.json` were lost (cause/issue: switching models with `/model` at startup was suspected of rewriting the settings file; this is a single-user report and no official confirmation from the product side has been found).
Session & history lossUnverified reportFirst-party report
Are there reports of Claude Code deleting files or data?
Yes. This list has 20 reports of lost or destroyed files and data. Most are unverified reports from users, and the conditions and causes have not been confirmed. You can read the original report through the source links on each row.
Did the vendor confirm these incidents?
No. Of the 34 cases, 33 are unverified reports. A public issue is a report filed on the product's official repository, but it does not mean the vendor has accepted it as fact.
Is this page affiliated with the vendor of Claude Code?
No. It is an independent summary of publicly available reports and has no connection with the vendor of Claude Code. Requests for correction or removal are accepted through the contact link at the bottom of the page.
Each entry is based on the public statements, news articles or reports linked as evidence. Our service has not independently established these facts.
Certainty reflects the wording of the source. Confirmed: the affected party or authorities have confirmed harm. Possible: a potential leak or harm has been disclosed or reported, or the case involves allegations. Under investigation: whether harm occurred or its extent is being investigated. Unverified report: a report by a user or other involved party without confirmation by a third party or the provider.
Entries marked First-party report are user reports, such as those submitted to a product’s public issues. They do not mean the provider has acknowledged the report as fact.
Dates are the publication or disclosure dates of the sources, and may differ from when the incident occurred. For entries sourced from AIID, the date is the incident date listed in AIID.
Details may change with follow-up reports. Check the source links for the latest information.
Scope of coverage
AI development: Deletion, overwriting or destruction by AI coding agents; authentication or secret-handling flaws in AI-generated code or AI-built apps; supply-chain problems involving AI development tools or packages; attack code created with generative AI; and loss of history or data in AI development services. Deepfakes, general misinformation and autonomous driving are excluded.
Data leaks & unauthorized access: Cases publicly disclosed in Japan in 2026 whose details could be verified in statements by the affected party or a government agency.
Request a correction or removal
If an entry contains an error, or you would like to request a correction or removal, please contact us.