Hacked account ran up an $80K AI bill: no major provider offers a hard spend cap
MaverikSh · reddit · 2026-09-20
The author recounts a case where a compromised cloud account was used by an attacker to run image generation at scale, dodging free-tier limits with new projects — the bill topped $80K, and the provider only offered a partial "courtesy" write-off.
The core point isn't credential theft itself: none of the major AI providers let you set a hard, absolute spend cap. You can set alerts and soft budgets, but nothing stops a request at the door — whether it's a malicious actor or your own agentic loop gone sideways at 2am (retry loops without backoff, 40-turn agent chains, buggy batch reprocessing). "Alert me when spend crosses X" and "stop the request before it happens" are entirely different guarantees, and today nearly every provider only offers the first.
More from Infra
- Offer a DGX Station / GB300 as a sign-on bonus and any AI hire signs on the spot — Jasonio · 2026-09-20
- Is Now a Bad Time to Buy a Strix Halo for Local LLMs? RAM Crisis Doubts — -mattmason- · 2026-09-20
- Why this Local AI writer picked an AMD 395 / 128GB box for local LLMs — julianharris · 2026-09-20
- Cloudflare now lets you create Free accounts programmatically via API and OAuth — samgoodwin89 · 2026-09-20
- Wall Street pegs orbital data centers at up to $170B per GW; SpaceX camp says models repeat Starlink mistakes — elonmusk · 2026-09-20
- Meta to deploy in-house MTIA 450 chip in data centers in early 2027 to cut Nvidia reliance — emmanuelvivier · 2026-09-20