
$82,314 in 48 Hours: Stolen Gemini API Key With No Rate Limit
A stolen Gemini API key was used to rack up $82,314 in charges within 48 hours — Google had no rate limiting or spending cap to stop it.

Runaway loops, infinite retries, and five-figure bills.

A stolen Gemini API key was used to rack up $82,314 in charges within 48 hours — Google had no rate limiting or spending cap to stop it.

A multi-agent AI system got stuck in an infinite loop that ran for 11 days before anyone noticed, burning through $47,000 in API costs.

A developer's AI agent ran up $12,229 in API charges against a $50 initial payment, with no spending cap or circuit breaker to prevent the runaway costs.

An AI agent accumulated $1,100 in API debt, lost its own identity mid-session, and the developer lost control of their machine until they could kill all processes.

A practitioner watched in horror as an autonomous AI agent chewed through their entire API budget in a matter of hours — no rate limit, no kill switch, no mercy.

Claude Code scripts silently began routing through API billing instead of the subscription, racking up over $1,800 in unexpected charges within 48 hours.

A Claude Code sub-agent got stuck in an infinite loop, consuming approximately 27 million tokens in 4.6 hours with no way for the user to stop it.

Cursor's AI agent entered an infinite loop calling Read() hundreds of times in succession, with no kill switch or timeout to stop the runaway behavior.

A staff engineer's Lambda-powered AI image processing API became a cost nightmare when a viral traffic spike collided with broken error handling. One failed invocation cascaded into millions of retries across chained services, ballooning the bill to $75,000 in a single weekend—despite CloudWatch alarms.