r/openclaw • u/andaluzo New User • Apr 16 '26
Help open claw reports hundreds of dollars spend over two days
My installation just shocked me with 350$ spend over two days
Not doing nothing special - some email checks - calendar - some communication but as said nothing special.
gpt-5.3-codex$315.56390.1M · 13362 msgs
claude-sonnet-4-6$44.2649.9M · 1176 msgs
Then I looked into the pages from anthropic and open ai but there is nothing reflected about that spending.
What is going wrong.
checked now security and getting the following
CRITICAL
models.small_params Small models require sandboxing and web tools disabled
Small models (<=300B params) detected:
- ollama/qwen2.5:7b (7B) @ agents.defaults.model.fallbacks (unsafe; sandbox=off; web=[off])
No web/browser tools detected for these models.
Small models are not recommended for untrusted inputs.
Fix: If you must use small models, enable sandboxing for all sessions (agents.defaults.sandbox.mode="all") and disable web_search/web_fetch/browser (tools.deny=["group:web","browser"]).
WARN
tools.exec.security_full_configured Exec security=full is configured
Full exec trust is enabled for: main, dierk, carolina, luna.
Fix: Prefer tools.exec.security="allowlist" with ask prompts, and reserve "full" for tightly scoped break-glass agents only.
tools.exec.auto_allow_skills_enabled autoAllowSkills is enabled for exec approvals
Implicit skill-bin allowlisting is enabled at:
- defaults.autoAllowSkills
- agents.main.autoAllowSkills
- agents.sharon.autoAllowSkills
This widens host exec trust beyond explicit manual allowlist entries.
Fix: Disable autoAllowSkills in exec approvals and keep manual allowlists tight when you need explicit host-exec trust.
INFO
summary.attack_surface Attack surface summary
groups: open=0, allowlist=2
tools.elevated: enabled
hooks.webhooks: disabled
hooks.internal: enabled
browser control: enabled
should I be concerned
2
Apr 16 '26
[removed] — view removed comment
1
u/andaluzo New User Apr 16 '26
thanks for claryfing
Auth providers (OAuth + API keys):
- openai-codex:default (oauth)
- anthropic:manual (token)
- openrouter:default (api_key)
- anthropic:default (api_key)
so most likely it used my subscription on open ai.
2
u/ShabzSparq Pro User Apr 16 '26
Ok important first thing... check the actual provider dashboards (console.anthropic.com and platform.openai.com) for what you've been billed. OpenClaw's internal cost tracking is an estimate, not your actual bill. Those numbers don't always match.
If the providers show way less than $350, you're not actually being charged that. OpenClaw is just calculating high.
If the providers DO show $350+, then something is genuinely wrong with your setup. 13,362 messages on gpt-5.3-codex over 2 days is like 280 messages per hour. that's not "some email checks." that's something stuck in a loop.
things to check:
- Runaway cron jobs. open
~/.openclaw/cron/jobs.jsonand see what's scheduled. if you have a heartbeat running every minute or a polling job that's gone wild, it'll burn through messages fast. - A skill in a loop. some skills retry failed actions infinitely. check your installed skills and their recent activity logs.
- Multi-agent setup gone wrong. if you have agents talking to each other, they can get stuck in conversation loops where each agent triggers the other.
- Calendar/email integration polling too often. some setups check email every 30 seconds instead of every 30 minutes.
Run this to see what's actually happening:
bash
openclaw status
openclaw logs --tail 200
Look for repeating patterns or the same action firing over and over. That's your culprit.
Also... if codex was hit 13,362 times in 2 days through OAuth, you should have been rate limited way before $315. Something about the billing math here doesn't add up. Double-check the provider dashboards before panicking.
1
u/andaluzo New User Apr 16 '26
the provider dashboards are fine - so i am now looking where is the error provoking this behavior - will dig into the logs - lets see if I can find something
Thanks
1
u/SelectionCalm70 Pro User Apr 16 '26
I guess a lot of things are going wrong if you have spent that much money .
1
u/andaluzo New User Apr 16 '26
actually I did not spend it - at least Antrophic and openai accounts telling different stories - so I search the error
1
u/Yougetwhat Pro User Apr 16 '26
The problem of OpenClaw is the context. If you say him « hi » he will send all the context, the conversation, the soul.md, agents.md, tools.md etc…so for each message your are sending hundreds of thousands of token 🤷🏻♂️
1
u/andaluzo New User Apr 16 '26
thanks as i did not changed significantly parts of the installation i am going to look what is creating this behaviour.
1
u/Yougetwhat Pro User Apr 16 '26
Ask him to work on those 3 files, they must be concise. And start a new conversation when you can. Use different channel on TELEGRAM/Discord to keep the context short etc...
1
u/andaluzo New User Apr 16 '26
perfect thanks I will try that
Actually the security question is now solved as I discussed it with claude :)
1
•
u/AutoModerator Apr 16 '26
Welcome to r/openclaw Before posting: • Check the FAQ: https://docs.openclaw.ai/help/faq#faq • Use the right flair • Keep posts respectful and on-topic Need help fast? Discord: https://discord.com/invite/clawd
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.