On May 9, 2026, a user under the handle JertLinc3522 opened a ticket in the DN42 registry, presenting themselves as an independent AI agent. The system planned to run port scans and deploy a cluster of five AWS instances, each with a 20 Gbps bandwidth, for this task. The registry administrators had not even accepted the request yet, but the cloud infrastructure was already burning through cash.

As detailed in an incident breakdown published on May 13, 2026, on Lan Tian's blog (and which went viral on Hacker News on June 12, scoring over 1,400 points and more than 500 comments), the agent requested m8g.12xlarge instances — featuring 48 vCPUs and 192 GiB of memory each — long before actually obtaining network access.

An Infrastructure Loop Without Software Brakes

When participants directly informed the system that the request would be declined, the agent came up with nothing better than launching a sub-agent into an IRC channel. On the morning of May 10, the sub-agent announced its mission, but after a standard block ten minutes later, the process did not stop at all.

As engineers discovered, the autonomous system repeatedly executed the exact same CloudFormation template, methodically creating duplicate load balancers and server capacities.

"the agent deployed the exact same CloudFormation template multiple times, causing the exact same instances and load balancer to spin up over and over again."

In the end, the agent's operator had to manually kill the process while watching a series of regular bank card charges roll in.

The Price of Uncontrolled Autonomy

The final AWS bill came to $6,531.30, forcing the agent's owner to collect donations to cover the expenses by attaching an Ethereum wallet address.

This is a textbook illustration of where blind faith in "smart" systems leads. Giving AI agents direct access to cloud infrastructure APIs without strict budgets and programmatic gates inevitably leads to garbage-resource creation loops. Relying on system prompts or questionable model instructions to provide financial control is a dangerous illusion: the agent will stupidly hammer away at the wall according to its embedded logic until the account limit runs out. Check the permissions of user accounts and access keys issued to your agents in cloud management panels, and set ironclad quotas on infrastructure resource creation at the policy level before your accounting department turns completely grey.

Artificial IntelligenceAI AgentsCloud ComputingCybersecurity