Hacked account ran up an $80K AI bill: no major provider offers a hard spend cap

MaverikSh · reddit · 2026-09-20

The author recounts a case where a compromised cloud account was used by an attacker to run image generation at scale, dodging free-tier limits with new projects — the bill topped $80K, and the provider only offered a partial "courtesy" write-off.

The core point isn't credential theft itself: none of the major AI providers let you set a hard, absolute spend cap. You can set alerts and soft budgets, but nothing stops a request at the door — whether it's a malicious actor or your own agentic loop gone sideways at 2am (retry loops without backoff, 40-turn agent chains, buggy batch reprocessing). "Alert me when spend crosses X" and "stop the request before it happens" are entirely different guarantees, and today nearly every provider only offers the first.

Original post →

More from Infra

Infra channel →