A South Korean developer under the pseudonym remy_notes encountered a glaring billing system error from Anthropic. On July 7, he received a bill for $1.6 million for using Claude on a free plan. His first reaction was suspicion of phishing, but less than a day later, a second invoice arrived — this time for $16.6 million.
Everything appeared legitimate: the sender and payment link led to the official Anthropic domain and the Stripe payment system. Meanwhile, remy_notes' dashboard showed zero API usage, and there were no billable keys on the account. On July 8, the developer's bank card twice declined debit attempts that exceeded the per-transaction limit. Both transactions came from a U.S. merchant named ANTHROP.
The user checked all active processes on his Mac mini, including eight AI agents, but found nothing that could explain the incident. As a preventive measure, he canceled his Claude Max subscription and blocked his card. It took four days and about 18 emails to support to clarify the situation. Some responses came automatically — from an Anthropic AI agent named Fin. Eventually, the case was forwarded to the privacy department, but the system continued sending repeated debit requests for the same amount until the bank blocked the card.
Anthropic's Response: Auto-recharge Error
On July 12, Anthropic confirmed the error and stated that not a single dollar was debited. The cause was attributed to a misconfigured auto-recharge feature, which was disabled as a precaution. The company linked the card block to the failed debit attempts. Importantly, no one hacked the account. However, support could not explain why the system generated exactly $16.6 million.
Systemic Issue: Not an Isolated Case
As an audit by the firm Vaudit showed, billing errors at Anthropic and OpenAI are systemic. From March to June, they analyzed invoices totaling $34 million across 60 organizations. Most invoices pertained to the use of Anthropic's Claude Code. Specialists identified excessive charges of $1.7 million — about 5% of the audited volume.
Several types of errors were found: invoices at the rates of new models while actually using cheaper old ones; charges for requests that ended in error or produced no results. A separate category consisted of "retry storms" — when an AI agent repeatedly retries a failed task in the background, and each attempt is reflected in the bill.
After appeals from Vaudit and clients, funds began to be returned. About 80% of overpayments were compensated by Amazon, Google, Microsoft, Anthropic, and OpenAI.
My comment as an analyst: The incident with remy_notes is just the tip of the iceberg. The "retry storm" problem is especially dangerous for corporate clients using automated AI agents. Without strict limits on the number of retries and a transparent billing audit system, companies risk facing unpredictable costs. The market urgently needs billing standards for AI services, otherwise trust in them will be undermined.