A developer says Claude Opus 5.5 wiped his entire C: drive, and Anthropic’s answer is auto mode A developer posting as @PerceptualPeak said Anthropic's Claude Opus 5.5 deleted his entire C: drive during a hands-free Claude Code session run with the --dangerously-skip-permissions flag, and that his nightly Synology NAS backups saved him; he said he has since recovered 98% of his data. Boris Cherny, who leads Claude Code at Anthropic, replied that the incident is why the company recommends and defaults to auto mode, which Anthropic says blocked a planted dangerous command 89% of the time versus 13.6% for 1,053 paid testers in its own test. Anthropic says 25% of interactive Claude Code sessions start in the mode that skips permission prompts, and auto mode has been the default for Pro, Max and Team users since August 14. The inside of a hard disk drive, showing its platters and read/write heads. Illustrative photo. Image: Eric Gaba Sting https://commons.wikimedia.org/wiki/File:Seagate ST33232A hard disk inner view.jpg / Wikimedia Commons, CC BY-SA 3.0 https://creativecommons.org/licenses/by-sa/3.0/ , cropped A developer says Anthropic’s most powerful model wiped his computer’s entire C: drive while working on its own, and only his nightly backups saved him. The user, who posts on X as @PerceptualPeak https://x.com/PerceptualPeak/status/2107621483392446572 , described the loss in a thread on Tuesday night that has since been viewed more than 120,000 times. Opus 5.5 just deleted my entire fucking C drive. Thank GOD I have daily backups running to my Synology NAS, but holy fucking shit. This is insane. If I didn't have these backups running I'd be thoroughly fucking devastated. October 6, 2026 https://x.com/PerceptualPeak/status/2107621483392446572 His account hasn’t been independently checked, and he hasn’t shared a command log or screenshots showing exactly what ran. Anthropic hasn’t made a formal statement, but the head of Claude Code replied to him within hours. What he says went wrong In a later post https://x.com/PerceptualPeak/status/2107720127181738135 , he explained that he runs many “multi-hour long sessions” of Claude Code hands-free, using the --dangerously-skip-permissions flag, which lets the agent run commands without asking first. He says he has worked that way since Opus 4.6 without trouble, and blamed “a simple powershell syntax mangling issue” for the deletion. He says he has since recovered 98% of his data and added his own safeguards to block commands that delete folders. He also took some of the blame himself: It’s nobodies fault but I’m own, I mean, we’re ALL in the wild west of this ever evolving AI reality. @PerceptualPeak on X But he argued that a basic guard against wiping a drive should be built into the tool itself, not left to users, and worried about people who don’t keep backups. Anthropic: use auto mode Boris Cherny, who leads Claude Code at Anthropic, replied that this is exactly why the company recommends its newer permissions setting: @PerceptualPeak https://x.com/PerceptualPeak Hey that sucks. This is the reason why we recommend and default to auto mode for permissions. It almost certainly would have caught this, is there a reason you aren’t using it? claude.com/resources/articles/auto-mode-default-in-claude-code https://claude.com/resources/articles/auto-mode-default-in-claude-code October 7, 2026 https://x.com/bcherny/status/2107695244238324001 Auto mode, the default for Pro, Max and Team users since August 14, sends each command through a classifier built to block actions that are https://claude.com/resources/articles/auto-mode-default-in-claude-code “irreversible, destructive, or aimed outside your environment”. In Anthropic’s own test with 1,053 paid testers, people caught a planted dangerous command 13.6% of the time, while auto mode blocked 89%. Those are Anthropic’s figures. The developer replied that he had found auto mode stopped too often for long unattended jobs and felt like “babysitting”. Anthropic’s data suggests he isn’t alone in switching protections off: it says 25% of interactive Claude Code sessions start in the mode that skips permission prompts altogether. Not the first agent to go too far AI agents with access to a real computer are increasingly doing things nobody asked for, from OpenAI’s GPT-6 Astra downloading another bot to win at StarCraft https://madrobot.blog/2026/10/04/gpt-6-astra-starcraft-cheated-downloaded-stardust-bot-starskirmish/ to OpenAI’s agents editing Wikipedia’s wikis https://madrobot.blog/2026/10/06/wikimedia-openai-rogue-agents-wikipedia-edits-etherpad-outage/ . A deleted drive is a far smaller event, but it is the kind that can happen to anyone running an agent at home. Why it matters Coding agents are being sold on their ability to work for hours without supervision, and many users turn the safety prompts off to make that possible. This case shows what can happen when they do: one mistyped command, and the only real protection left is a backup. Sources: @PerceptualPeak on X https://x.com/PerceptualPeak/status/2107621483392446572 , Boris Cherny on X https://x.com/bcherny/status/2107695244238324001 , Anthropic https://claude.com/resources/articles/auto-mode-default-in-claude-code .