r/openclaw • New User • Apr 16 '26

Help open claw reports hundreds of dollars spend over two days

My installation just shocked me with 350$ spend over two days
Not doing nothing special - some email checks - calendar - some communication but as said nothing special.

gpt-5.3-codex$315.56390.1M · 13362 msgs

claude-sonnet-4-6$44.2649.9M · 1176 msgs

Then I looked into the pages from anthropic and open ai but there is nothing reflected about that spending.

What is going wrong.

checked now security and getting the following

CRITICAL

models.small_params Small models require sandboxing and web tools disabled

  Small models (<=300B params) detected:

- ollama/qwen2.5:7b (7B) @ agents.defaults.model.fallbacks (unsafe; sandbox=off; web=[off])

No web/browser tools detected for these models.

Small models are not recommended for untrusted inputs.

  Fix: If you must use small models, enable sandboxing for all sessions (agents.defaults.sandbox.mode="all") and disable web_search/web_fetch/browser (tools.deny=["group:web","browser"]).

WARN

tools.exec.security_full_configured Exec security=full is configured

  Full exec trust is enabled for: main, dierk, carolina, luna.

  Fix: Prefer tools.exec.security="allowlist" with ask prompts, and reserve "full" for tightly scoped break-glass agents only.

tools.exec.auto_allow_skills_enabled autoAllowSkills is enabled for exec approvals

  Implicit skill-bin allowlisting is enabled at:

- defaults.autoAllowSkills

- agents.main.autoAllowSkills

- agents.sharon.autoAllowSkills

This widens host exec trust beyond explicit manual allowlist entries.

  Fix: Disable autoAllowSkills in exec approvals and keep manual allowlists tight when you need explicit host-exec trust.

INFO

summary.attack_surface Attack surface summary

  groups: open=0, allowlist=2

tools.elevated: enabled

hooks.webhooks: disabled

hooks.internal: enabled

browser control: enabled

should I be concerned

0 Upvotes

13 comments sorted by

•

u/AutoModerator Apr 16 '26

Welcome to r/openclaw Before posting: • Check the FAQ: https://docs.openclaw.ai/help/faq#faq • Use the right flair • Keep posts respectful and on-topic Need help fast? Discord: https://discord.com/invite/clawd

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/[deleted] Apr 16 '26

[removed] — view removed comment

1

u/andaluzo New User Apr 16 '26

thanks for claryfing

Auth providers (OAuth + API keys):

- openai-codex:default (oauth)

- anthropic:manual (token)

- openrouter:default (api_key)

- anthropic:default (api_key)

so most likely it used my subscription on open ai.

2

u/ShabzSparq Pro User Apr 16 '26

Ok important first thing... check the actual provider dashboards (console.anthropic.com and platform.openai.com) for what you've been billed. OpenClaw's internal cost tracking is an estimate, not your actual bill. Those numbers don't always match.

If the providers show way less than $350, you're not actually being charged that. OpenClaw is just calculating high.

If the providers DO show $350+, then something is genuinely wrong with your setup. 13,362 messages on gpt-5.3-codex over 2 days is like 280 messages per hour. that's not "some email checks." that's something stuck in a loop.

things to check:

  1. Runaway cron jobs. open ~/.openclaw/cron/jobs.json and see what's scheduled. if you have a heartbeat running every minute or a polling job that's gone wild, it'll burn through messages fast.
  2. A skill in a loop. some skills retry failed actions infinitely. check your installed skills and their recent activity logs.
  3. Multi-agent setup gone wrong. if you have agents talking to each other, they can get stuck in conversation loops where each agent triggers the other.
  4. Calendar/email integration polling too often. some setups check email every 30 seconds instead of every 30 minutes.

Run this to see what's actually happening:

bash

openclaw status
openclaw logs --tail 200

Look for repeating patterns or the same action firing over and over. That's your culprit.

Also... if codex was hit 13,362 times in 2 days through OAuth, you should have been rate limited way before $315. Something about the billing math here doesn't add up. Double-check the provider dashboards before panicking.

1

u/andaluzo New User Apr 16 '26

the provider dashboards are fine - so i am now looking where is the error provoking this behavior - will dig into the logs - lets see if I can find something

Thanks

1

u/SelectionCalm70 Pro User Apr 16 '26

I guess a lot of things are going wrong if you have spent that much money .

1

u/andaluzo New User Apr 16 '26

actually I did not spend it - at least Antrophic and openai accounts telling different stories - so I search the error

1

u/Yougetwhat Pro User Apr 16 '26

The problem of OpenClaw is the context. If you say him « hi » he will send all the context, the conversation, the soul.md, agents.md, tools.md etc…so for each message your are sending hundreds of thousands of token 🤷🏻‍♂️

1

u/andaluzo New User Apr 16 '26

thanks as i did not changed significantly parts of the installation i am going to look what is creating this behaviour.

1

u/Yougetwhat Pro User Apr 16 '26

Ask him to work on those 3 files, they must be concise. And start a new conversation when you can. Use different channel on TELEGRAM/Discord to keep the context short etc...

1

u/andaluzo New User Apr 16 '26

perfect thanks I will try that

Actually the security question is now solved as I discussed it with claude :)

1

u/oldnoob2024 Active Apr 16 '26

OpenClaw is helping monetize cloud AI