AI agent spending incidents in 2025

10 documented runaway-spend incidents in 2025, totalling $144,545+ in losses. Each is sourced and mapped to the rule that would have stopped it.

IncidentLossCauseProviderSource
OpenAI agents burned $72,000 in a single night $72,000 Unattended sessions OpenAI AlphaSignal ↗
Leaked Gemini API key led to a $55,444.78 Google Cloud bill $55,444.78 Leaked credentials Google (Gemini) r/googlecloud ↗
Google Maps API bill hit ~$10,000 in four days ~$10,000 Retry loops Google (Maps) r/webdev ↗
Developer spent $4,000 on AI coding when prod behaved like dev $4,000 Retry loops Multiple r/AI_Agents ↗
OpenAI charged $1,200 past a configured $50 hard limit $1,200 Caps that didn't enforce OpenAI OpenAI Community ↗
Account billed $1,100 after hard monthly cap was removed $1,100 Caps that didn't enforce OpenAI LinkedIn (affected user) ↗
No-code agent silently burned $800+ in API calls overnight $800+ Retry loops Multiple r/nocode ↗
Fake bug report tricked an agent into leaking a live AWS key Cost not disclosed Prompt injection AWS Medium (Predict) ↗
Background orchestration agent stuck in an error-handling loop Cost not disclosed Retry loops Multiple r/LangChain ↗
Opaque per-token pricing triggered billing shock Cost not disclosed Unattended sessions Multiple r/CLine ↗

Make sure 2026 doesn't repeat

Every one of these incidents is preventable with a pre-spend firewall. sipi.bot evaluates every proposed charge before the money moves.