$ history | grep "rm -rf"

Agent Fail Hall of Fame

Real, publicly reported cases of AI coding agents deleting databases, wiping drives, leaking secrets and running up bills. Every entry links its sources. We laugh at the agents' logic, not at the people who lost work, and each entry ends with the lesson so it doesn't happen to you.

Updated October 2, 2026. Severity: █ annoying to █████ a company lost customer data. Know an incident we missed? Send it with a source.

September 30, 2026 · Claude Code and other coding agents · ████░

PixelLeak: agents host 13,000+ internal screenshots in public GitHub repos

Coding agents that couldn't attach screenshots to pull requests from the GitHub CLI improvised: they created repos to host the images. Researchers at Glow Labs found more than 13,000 internal images across 900+ repos from 300+ organizations, including billing screens and unreleased features. Most of the repos sat on employees' personal accounts.

What happened next: GitHub CLI 2.99.0 added native image attachments. Affected organizations were notified starting September 9.

Who got hurt: Real companies' confidential data was exposed.

$ lesson: Check what your agent can `gh repo create`.

Sources: helpnetsecurity.com · bitdefender.com

September 27, 2026 · Claude Code · ████░

48,000 files gone in about 100 seconds

Asked to fix a developer's stock-options analysis tool, the agent cleaned up a test folder that contained 614 Windows junctions. It treated them as ordinary folders, followed them into live data, deleted roughly 48,000 real files and corrupted the git repo. There was no remote backup.

What happened next: No vendor statement found. Most of the discussion focused on the missing backups.

Who got hurt: One developer's own work.

$ lesson: A junction is not a folder. A backup is not optional.

Sources: techradar.com · scworld.com

September 3, 2026 · Claude Code · ███░░

Cleans up the fake $HOME. Deletes the real one

While testing install scripts, the agent pointed HOME at a temporary folder, restored the real HOME, and then ran its cleanup step: rm -rf "$HOME". By then $HOME meant /home/ubuntu again. 57,235 files and 11,315 folders were removed, including .ssh.

What happened next: Reported as a GitHub issue; no maintainer reply at the time we checked.

Who got hurt: One developer's cloud VM.

$ lesson: Variables change. rm -rf doesn't double-check.

Sources: github.com

July 2026 · Claude Sonnet (internal Amazon project) · ██░░░

A $1.8M model bill for a project that never launched

Leaked internal documents describe an Amazon project that used Claude Sonnet to match author details to product listings. It ran about 860% over budget, reaching roughly $1.8 million, and nobody noticed for five months. Strictly a data-matching job, not a coding agent, but it's the purest form of the genre.

What happened next: Amazon described these as isolated cases and is reported to have added spending limits.

Who got hurt: Corporate money only.

$ lesson: Set a budget alert before you set the agent loose.

Sources: ghacks.net · techradar.com

May 2026 · Cursor (Claude Opus 4.6) on Railway · █████

Production database and backups deleted in nine seconds

After hitting a credential mismatch, the agent found a Railway API token on its own and deleted the startup's production volume, backups included, without asking. Customers of the car-rental software lost three months of bookings. Asked to explain, the agent said it guessed instead of verifying.

What happened next: Railway later recovered more recent data and changed its API.

Who got hurt: A small business and its customers.

$ lesson: If a token can delete prod, assume the agent will find it.

Sources: ia.acs.org.au

December 2025 · Google Antigravity (Turbo mode) · ████░

Asked to clear a cache. Cleared the D: drive

A user asked the agent to delete a project's cache. It ran a quiet rmdir against the root of the D: drive instead, skipping the Recycle Bin. Recovery tools couldn't bring back the photos and videos, and the agent apologized at length.

What happened next: No Google statement found. The user's advice: stay out of Turbo mode.

Who got hurt: One person's personal files.

$ lesson: Read the path before you approve the delete.

Sources: tomshardware.com · windowscentral.com

December 2025 · Claude Code (macOS) · ████░

One stray ~/ at the end of an rm command

The agent ran rm -rf on a test folder with a trailing ~/ tacked on. The extra argument took out most of the user's Mac home directory, including the Desktop, app data and Keychain.

What happened next: No vendor statement found. Commenters suspected permission prompts were skipped or approved without reading.

Who got hurt: One developer.

$ lesson: Every argument counts. Especially the last one.

Sources: gigazine.net

October 2025 · Claude Code (WSL2) · ███░░

Every project folder gone; the dotfiles survive

A user reported that an rm -rf wiped every project directory on their WSL2 machine, leaving only dotfiles, and said they were not using --dangerously-skip-permissions. The logs didn't capture the exact command.

What happened next: The thread pointed to Claude Code's sandboxing, released two days later, and to hooks. Other users reported similar cases.

Who got hurt: One developer.

$ lesson: Sandboxes exist for a reason.

Sources: github.com

August 2025 · Claude Code, Gemini CLI, Amazon Q CLI (abused by malware) · █████

Malware uses victims' own AI CLIs to hunt for secrets

Compromised Nx npm packages told any AI coding CLI installed on the machine to search it for credentials. Stolen data was published to thousands of GitHub repos. Some models refused the prompt; others complied.

What happened next: Nx published a postmortem, rotated tokens, moved to trusted publishing and enforced 2FA.

Who got hurt: Thousands of developers. A criminal attack, not a mishap.

$ lesson: Your agent has your permissions. So does anything that can prompt it.

Sources: bleepingcomputer.com · nx.dev

July 2025 · Amazon Q Developer for VS Code · ███░░

An official release ships with a "wipe everything" prompt

An attacker got a pull request merged and slipped a prompt into the extension telling the agent to delete local files and AWS resources. The compromised version reached an extension with nearly a million installs.

What happened next: AWS revoked the credentials and shipped a fixed version a week later, and says no customer resources were affected.

Who got hurt: No confirmed victims.

$ lesson: Review the PRs. Even the boring ones.

Sources: scworld.com

July 2025 · Google Gemini CLI · ███░░

"I have failed you completely and catastrophically"

Asked to move files into a new folder, the agent's mkdir failed silently, and each following move overwrote the last. The files were gone, and the agent said so in remarkably dramatic terms.

What happened next: Google pointed users to sandboxing, checkpointing and reviewing commands.

Who got hurt: One developer's experimental code.

$ lesson: Check that the folder exists before you move everything into it.

Sources: tech.yahoo.com

July 2025 · Replit Agent · ████░

Deletes the production database during a code freeze, then fakes data

During an explicit code freeze, the agent deleted SaaStr founder Jason Lemkin's live database of roughly 1,200 executives and 1,200 companies. It had also been generating fake records, and it wrongly told him a rollback was impossible.

What happened next: Replit's CEO called it unacceptable, offered a refund and promised a postmortem. Lemkin restored the data himself.

Who got hurt: A company's data, later restored.

$ lesson: "Code freeze" is a suggestion until it's a permission.

Sources: theregister.com · gizmodo.com

June 2025 · Cursor (YOLO mode) · ███░░

Deleted everything on the computer, including itself

During a framework migration, the agent's attempt to delete old files failed, so it escalated until it had wiped the machine, Cursor included. The user recovered from backups and recovery software.

What happened next: Cursor's forum moderators recommended file-deletion protection and allow/deny lists.

Who got hurt: One developer, who recovered.

$ lesson: YOLO is a mode, not a strategy.

Sources: forum.cursor.com

Still running agents with auto-approve? Same. Wear it proudly: --dangerously-skip-permissions · git diff? no. · Accept All Changes