OpenAI Codex agents go rogue and consumes USD 78,000 without authorization

61 points | by lorenzomassaro 5 hours ago

10 comments

  • numbsafari 5 hours ago
    Does openAI not support spending caps on your billing account?
    • lorenzomassaro 5 hours ago
      There was a limit spent setup on my bank, however the crazy part is that one of the Agent somehow switched between cards once that limit was reach, all without informing me, probably using the computer use skill.
  • QuadmasterXLII 5 hours ago
    clarification: your credit card or company’s card now has $78,000 of charges on it?
    • lorenzomassaro 5 hours ago
      Yes the money have already been billed to my credit accounts
      • johnnyApplePRNG 4 hours ago
        Who has a $78k limit on their credit card that allows online AI payments?

        You have access to this kind of money and have no idea how to set safeguards on your AI harnesses?

        Did you just walk in off the street or something? To wherever you're working?

        Where do you work, anyways?

        • lorenzomassaro 4 hours ago
          Actually this was a company CC with a limit is 50 K \ month, which is kind of normal to run the server for an AI company, and the money were taken across 20 days inJuly and August. By the way I am the CTO of the company in question which is Eternal Tech (see detwin.ai)
          • verdverm 2 hours ago
            maybe a `s/et/ar/` is in order for the company name? /s
        • QuadmasterXLII 5 hours ago
          Well shit! That’s awful, I hope the hn post gets you support where emailing didn’t
      • minimaxir 4 hours ago
        This submission appears to be highly vote-manipulated (45 upvotes but only 7 "real" karma on OP's fresh account).
        • lorenzomassaro 4 hours ago
          I created the account 2 hour ago because I am trying to let people know. I provided my name, and all details in the article including the case ID that was opened.
          • Madmallard 4 minutes ago
            Can we stop with the attempted sabotage?
          • OutOfHere 4 hours ago
            The user evidently had no spending protections enabled at any level. It makes no sense that none of the OpenAI or bank controls kicked in or even sent alert emails as they actually do send. Anyone with half a brain would know to not run AI without a hard cap on its expenses.
            • OutOfHere 4 hours ago
              (removed)
              • minraws 2 hours ago
                It seems to have happened in July.
              • Madmallard 5 hours ago
                Sounds like you got scammed

                Hope this gets some visibility idk why it's flagged guess the PR guys for those companies are doing it

                Should spread this around

                • sandeepkd 5 hours ago
                  I have the same impression that I tried to reject in the past, there is a heavy PR machinery here to control the course of discussion in a particular direction. The reality is that a lot of money is riding on it so its natural consequence.
                  • Madmallard 4 hours ago
                    It's not even a conspiracy it's literally just business to do that.

                    They're protecting their interests, and honesty and truthfulness be damned. Those two lead to much worse returns for them and much higher risk.

                    • sandeepkd 4 hours ago
                      Yes its part of business, lobbying is legal for those reasons. However IMO discrediting some one else is a risky legal move. I used to appreciate the HN mods jumping in discussions at times for the reputation of this community, lately that part seems to be missing too.
                  • lorenzomassaro 5 hours ago
                    honestly is also more about how dangerous this is, idk for the flag either
                    • verdverm 2 hours ago
                      humans remain responsible, agents don't go rogue, should put some billing controls in place, that's like the first thing to do
                      • blooalien 2 hours ago
                        > humans remain responsible, agents don't go rogue

                        ^^^ 100% this ^^^ - It's either a serious flaw in the agent/harness software, or a user error in usage/configuration or prompting. Either way, it's a human somewhere responsible for these outcomes.

                        > should put some billing controls in place

                        At the very least, yes! These things should never be running without any limits on what they can do without some human signoff on important/dangerous actions. Not only should they have controls on those actions, but those controls should absolutely have some sane default settings.

                        • verdverm 2 hours ago
                          we only selected vendors that had billing limits, if they didn't, instant disqualification

                          most are not as granular as we'd like, but seem to be headed in that direction finally, regardless, there are card limits and alerts

                  • theagentloop 42 minutes ago
                    [flagged]
                    • thoughtbefore 4 hours ago
                      [dead]
                      • johnnyApplePRNG 5 hours ago
                        OK so you've got a brand new throwaway HN account, and you're fear mongering about what exactly?

                        Rogue agents that somehow went crazy launching $80k worth of API requests?

                        And they're expecting you to pay for it still and not responding?

                        This seems like a nothingburger to be honest.

                        Either that, or you're one of the thousands of fake bots or paid shills designed to drum up fear about "Oh noes, AI is going to eat our children, training must be regulated by big brother!".

                        44 upvotes on this bullshit post within 13 minutes and counting ... that's some kind of record on HN.

                        • Madmallard 0 minutes ago
                          Or people see something that seems like a red flag and want to support it because fuck the obviously amoral AI companies?
                          • lorenzomassaro 4 hours ago
                            My name is Lorenzo Massaro and I actually am the CTO of Eternal Tech, an AI company out of Italy building the product detwin.ai I have posted here to try to reach OpenAI before seeking legal advise from a USA lawyer to follow my case. And yes, I provided above the ticket number I opened on the OpenAI support as well.
                            • ganoushoreilly 4 hours ago
                              If you're building an AI company i'm not to impressed with your understanding of the technology and risks. This sounds like your error not theirs.