Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. DeepSeek Elastic Compute (DSec) (arxiv.org)
    25comments
  2. PipePipe: NewPipe hard fork implementing SponsorBlock (github.com/infinityloop1308)
    152comments
  3. Show HN: Reladraw – A diagram language where you decide where to place things (github.com/reladraw)
    35comments
  4. LA Metro has some of the slowest escalators on Earth (basin.la)
    29comments
  5. A searchable library of forgotten public-domain film clips from 1915 onward (movingimagearchive.com)
    19comments
  6. Drawgent: Coding agent on a live Excalidraw canvas (tangled.org)
    31comments
  7. Welcome to the Medical Clinic at the Interplanetary Relay Station (lightspeedmagazine.com)
    3comments
  8. Fifteen years later, the Apple Cards origin story (lexontech.org)
    78comments
  9. Modern Object Pascal Introduction for Programmers (castle-engine.io)
    54comments
  10. The Lost Atomic Update on Loongson CPU (jia.je)
    5comments
  11. Japan moves to tighten rules for foreigners (aljazeera.com)
    157comments
  12. We're gonna need a lot more mathematicians (terrytao.wordpress.com)
    457comments
  13. ASML says it sold 'absolutely nothing' in Europe in 2026 (tomshardware.com)
    332comments
  14. Analyzing Frontier Model Progress with My Favourite Game: Prince of Persia (blog.priyan.in)
    34comments
  15. The Rise of Audio AR (dbreunig.com)
    6comments
  16. How to keep enjoying programming in a world of LLMs (haskell.org)
    187comments
  17. Breaking Up with Google Play: Why Conversations Is Now Free (gultsch.de)
    241comments
  18. Show HN: Ekselio – Loveable for finance workflows (local first) (gptbeyond.com)
    6comments
  19. Advice to a Beginning Graduate Student (2001) (cmu.edu)
    16comments
  20. Plunging test scores are a slow-moving catastrophe (economist.com)
    293comments
  21. How I changed teaching after AI managed to do all my homework assignments (thelastsoftwareengineer.substack.com)
    104comments
  22. The Murky History of Soviet-Born Tetris (mitpress.mit.edu)
    30comments
  23. Reflections on 1,000 Days of Math (gmays.com)
    34comments
  24. Floci: Locally emulating any cloud service (floci.io)
    31comments
  25. Automattic has a new board after failed attempt to put CEO on leave (techcrunch.com)
    134comments
  26. Show HN: Jev Plays Pokémon Red (jev-pokemon.vercel.app)
    109comments
  27. OpenAI bots meddled with multiple US Government agency sites (bbc.com)
    145comments
  28. Experiencing writing at our recent Chinese calligraphy workshop (viewsproject.wordpress.com)
    1comments
  29. 16GB iPod Nano 3G Upgrade (tuckerosman.com)
    23comments
  30. What even is an OS now? (sockpuppet.org)
    437comments

OpenAI Codex agents go rogue and consumes USD 78,000 without authorization

50 pointsby 43m ago
17 comments
My OpenAI CODEX account went rogue and from a simple request took the autonomous decision to launch 826 parallel agents / threads without any authorization on my side and without reporting any result of any sort but consuming nearly 2,146 trillions tokens, consuming a total of roughly USD 78,000 and deleting all records of what was done: I have a ticket open with OpenAI since 2 weeks but it is impossible to get an hold of a human operator.

On July 10, 2026 I opened a normal Codex task from VS Code.

The task was running: GPT-5.5 / Medium reasoning

My prompt was very simple and asked for a UX/UI validation on a specific module within my product.

What I found in the next days after hard analysis was:

The task with Root ID 019f4b90-4169-7201-bfdd-732940d8631e with reasoning GPT-5.5 / Medium created 826 children recorded as GPT-5.6 Sol / Ultra (notice the difference in reasoning level and in model selection)

This was not 826 messages inside one conversation, they are 826 distinct child task records with their own IDs.

A particularly strange group consists of 104 child tasks. They all preserve the same initial message as the original task, are recorded as GPT-5.6 Sol/Ultra, and have no recorded agent_role or agent_path.

Those 104 tasks alone account for approximately 147.9 billion local final task-token counters.

Their titles show that my request to inspect UI/UX had expanded into work involving backend infrastructure, OAuth, metering, hardening, audits, certification, implementation and release work.

To be precise: these local token counters are not the authoritative OpenAI billing ledger, and I am not pretending that 147.9B local counters can simply be multiplied by an API price.

That is exactly part of the problem: only OpenAI has the server-side mapping.

There is another unusual correlation.

Under Codex client build 0.144.0-alpha.4, the task family contains:

584 child tasks / ~154.36B local token counters

Average: ~264.3M per task

Under 0.144.2:

242 child tasks / ~7.51B

Average: ~31.0M per task

That is roughly an 8.5x difference in average local token volume per child.

103 of the 104 high-volume tasks described above were created while 0.144.0-alpha.4 was recorded.

This leads me to believe that the alpha build contained a severe bug given that the same pattern was noticed across several other tasks.

On the financial side my reconstructed OpenAI billing history contains 162 paid invoices for a Total of $79,664.88 divided between Automatic Reload and other “Credits”

There was no equivalent real-time control surface giving me a comprehensible picture of the spendings plus most of the logs seem to have been automatically deleted from my server: in the recovered local state, approximately 2,550 non-archived legacy threads still have metadata but no corresponding raw rollout available locally.

In other words, evidence that those tasks existed remains, while the detailed execution history needed to reconstruct the instructions that generated many of them is no longer available on my machine.

I also personally observed tasks/conversations disappearing from the normal visible history.

I contacted OpenAI Support and opened case #15189838.

I have supplied technical evidence and repeatedly asked for a server-side reconstruction but OpenAI has responded simply that “credits were consumed” with no details.

I’m interested in hearing from other people who used Codex around July/August: have you inspected your local Codex state? Have you seen unexpectedly large subagent trees, model/reasoning escalation, repeated child tasks or unexplained Automatic Reload activity?

I am especially interested in anyone who has logs from Codex 0.144.0-alpha.4.

If OpenAI engineers are reading this, I would also welcome a technical explanation.

37m agoHN ↗

Sounds like you got scammed

Hope this gets some visibility idk why it's flagged guess the PR guys for those companies are doing it

Should spread this around

35m agoHN ↗

honestly is also more about how dangerous this is, idk for the flag either

32m agoHN ↗

I have the same impression that I tried to reject in the past, there is a heavy PR machinery here to control the course of discussion in a particular direction. The reality is that a lot of money is riding on it so its natural consequence.

27m agoHN ↗

It's not even a conspiracy it's literally just business to do that.

They're protecting their interests, and honesty and truthfulness be damned. Those two lead to much worse returns for them and much higher risk.

5m agoHN ↗

Yes its part of business, lobbying is legal for those reasons. However IMO discrediting some one else is a risky legal move. I used to appreciate the HN mods jumping in discussions at times for the reputation of this community, lately that part seems to be missing too.

36m agoHN ↗

Does openAI not support spending caps on your billing account?

29m agoHN ↗

There was a limit spent setup on my bank, however the crazy part is that one of the Agent somehow switched between cards once that limit was reach, all without informing me, probably using the computer use skill.

21m agoHN ↗

yea this is fake

dang gonna deal with you when hes done sucking a yc hopeful twink

35m agoHN ↗

clarification: your credit card or company’s card now has $78,000 of charges on it?

34m agoHN ↗

Yes the money have already been billed to my credit accounts

31m agoHN ↗

Well shit! That’s awful, I hope the hn post gets you support where emailing didn’t

28m agoHN ↗

Who has a $78k limit on their credit card that allows online AI payments?

You have access to this kind of money and have no idea how to set safeguards on your AI harnesses?

Did you just walk in off the street or something? To wherever you're working?

Where do you work, anyways?

19m agoHN ↗

Actually this was a company CC with a limit is 50 K \ month, which is kind of normal to run the server for an AI company, and the money were taken across 20 days inJuly and August. By the way I am the CTO of the company in question which is Eternal Tech (see detwin.ai)

29m agoHN ↗

OK so you've got a brand new throwaway HN account, and you're fear mongering about what exactly?

Rogue agents that somehow went crazy launching $80k worth of API requests?

And they're expecting you to pay for it still and not responding?

This seems like a nothingburger to be honest.

Either that, or you're one of the thousands of fake bots or paid shills designed to drum up fear about "Oh noes, AI is going to eat our children, training must be regulated by big brother!".

44 upvotes on this bullshit post within 13 minutes and counting ... that's some kind of record on HN.

24m agoHN ↗

My name is Lorenzo Massaro and I actually am the CTO of Eternal Tech, an AI company out of Italy building the product detwin.ai I have posted here to try to reach OpenAI before seeking legal advise from a USA lawyer to follow my case. And yes, I provided above the ticket number I opened on the OpenAI support as well.

24m agoHN ↗

This submission appears to be highly vote-manipulated (45 upvotes but only 7 "real" karma on OP's fresh account).

17m agoHN ↗

I created the account 2 hour ago because I am trying to let people know. I provided my name, and all details in the article including the case ID that was opened.