openai / openai/codex

Quota depleted instantly after reset; Unauthorized/Anomalous usage detected (214 rounds on unused models)

Open
#41,310 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

auth bug rate-limits
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

I am reporting a critical issue where my quota was depleted almost immediately after the daily reset. Upon reviewing the usage logs, I found a massive spike in activity that I did not initiate.
Timeline & Incident Details:
Quota Reset Time: Today at 15:59 (Please specify timezone, e.g., UTC+8)
Depletion Time: Within 10 minutes of the reset (by approx. 16:09).
The Anomaly: My entire quota was consumed without any active sessions or manual input from me during this window.
Evidence from Usage Logs (See Attached Screenshot):
The usage dashboard for Aug 27, 2026, shows a total of 214 rounds consumed across multiple models that I do not typically use or have not accessed recently:
gpt-5.6-sol: 103 rounds
gpt-5.6-luna: 38 rounds
gpt-5.5: 28 rounds
gpt-5.4-mini: 21 rounds
gpt-5.6-terra: 16 rounds
gpt-5.4: 8 rounds
Why this is suspicious:
Volume: 214 rounds in a short period is impossible for manual human interaction.
Model Distribution: The usage is scattered across many different model versions (sol, luna, terra, etc.). I did not switch between these models, nor do I have automated scripts configured to cycle through them.
Timing: This happened right after the reset, suggesting a potential race condition, a billing system error, or unauthorized access to my API key/session.
Request:
Investigate Logs: Please check the server-side logs for my account around 15:59 – 16:09 today and the全天 of Aug 27. Identify the IP addresses or client IDs associated with these 214 requests.

Image

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the usage dashboard evidence and the server-side account logs for 15:59–16:09 and the full Aug 27 window. Check which IP addresses or client IDs generated the 214 requests and whether the quota reset or accounting path is involved. Done means the request source and underlying cause are identified, with the appropriate remediation path documented.

Written by the indexing model from the issue text.

Assessment

Domain
backend, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.