Skip to main content

xAI Billing Overdraft: HackerOne closed an API logic flaw as "intended model behavior"

0
Medium
Published: 09/11/2026 (09/11/2026, 14:43:09 UTC)
Source: Reddit Cybersecurity

Description

A logic flaw was discovered in xAI's API Gateway billing enforcement that allowed prepaid balance limits to be bypassed, enabling continued API usage on a zero balance and causing billing overdrafts. HackerOne closed the vulnerability report as out-of-scope, classifying it as "intended model behavior," despite it being an infrastructure billing logic issue. The vendor subsequently updated their API pricing and billing limits shortly after public disclosure, indicating mitigation of the reported issue.

Reddit Discussion

r/cybersecurity·posted by u/F-538
00

Quick note: English isn't my native language so I used AI to help clean up the text/translation, but all technical details, logs, and screenshots are mine.

I wanted to share a recent disclosure case regarding xAI's API Gateway billing enforcement to get feedback from the community on how infrastructure logic flaws are evaluated against broad LLM scope exclusions.

The Vulnerability & Impact
I identified a logic flaw in xAI's API Gateway regarding prepaid balance enforcement. The gateway failed to terminate sessions when an account hit $0, allowing an attacker to bypass prepaid limits, force an account into a deep negative balance (billing overdraft), and consume backend compute resources without authorization.

HackerOne's Response
HackerOne completely closed the report, classifying it as out-of-scope "intended model behavior." When escalated to H1 Mediation—pointing out that an API billing gateway failure is an infrastructure/billing logic issue rather than a model safety concern—they responded:

"The billing overdraft is a downstream consequence of the same unbounded resource consumption that the program considers out of scope. The root cause and the scope exclusion are the same regardless of which layer the impact surfaces on."

On July 28, Mediation permanently closed the ticket, refusing further re-examination.

Initial "Duplicate" Classification
Prior to claiming the issue was out-of-scope, triage initially marked the report as a "Duplicate" simply because the PoC prompt string matched a prompt from another report that I had authored myself. It was a 100% unique, custom prompt created by me, and while one prompt triggered two completely distinct infrastructure bugs across two reports, triage lazily marked the second report as a duplicate based solely on input string matching. Support only re-examined it after an initial post on X, at which point they pivoted to the "intended model behavior" exclusion.

Timeline & Vendor Mitigation
Post on X: I published a thread on X detailing the issue and challenging the classification of an API billing logic flaw as "intended model behavior".

Vendor Action: Just a couple of hours after my follow-up post on X calling out HackerOne's triage, xAI sent out an official API pricing update email notifying users about changes to tool-call billing to restrict data fetch volume—initiating mitigation for the exact vector I reported. (A cosmic coincidence, surely?)

Full Screenshots & Timeline Proof: https://imgur.com/a/yTcuqLG

TL;DR: Found an API Gateway logic flaw in xAI that bypassed prepaid balance limits, allowing continued requests on a $0 balance and causing billing overdrafts. HackerOne closed it as out-of-scope "intended model behavior" (and initially marked it duplicate purely based on input prompt string matching). The vendor updated their API billing limits just hours after I published a post on X (even with barely any views). Is a gateway/auth-level billing flaw really "model behavior"?

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 15:31:56 UTC

Technical Analysis

The reported issue involves a logic flaw in xAI's API Gateway where sessions were not terminated upon reaching a zero prepaid balance. This allowed an attacker to continue making API requests, forcing the account into a negative billing overdraft and consuming backend compute resources without authorization. HackerOne triaged the report initially as a duplicate based on prompt string matching, then closed it permanently as out-of-scope under the "intended model behavior" exclusion, arguing the billing overdraft was a downstream effect of unbounded resource consumption. The vendor later issued an API pricing update restricting data fetch volumes, effectively mitigating the flaw.

Potential Impact

The flaw allowed unauthorized resource consumption beyond prepaid limits, potentially causing unexpected billing charges and resource exhaustion. This could lead to financial loss for users and unauthorized backend resource usage. However, no known exploits in the wild were reported, and the vendor's subsequent pricing update suggests the issue was addressed.

Defensive Guidance

The vendor has implemented API pricing and billing limit updates shortly after public disclosure, which mitigate the reported billing overdraft vector. HackerOne considers the issue out-of-scope and no official patch advisory is available. Users should review the vendor's updated API pricing and usage policies to ensure compliance and prevent overdraft scenarios.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa41ee491cc7f384856c353

Added to database: 09/11/2026, 15:31:48 UTC

Last enriched: 09/11/2026, 15:31:56 UTC

Last updated: 09/11/2026, 16:31:43 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses