:

CODEX ON AWS BEDROCK BILLING BUG INFLATES CHARGES 10X

INDUSTRY DESK1 MIN READ
FRI, AUG 21, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A billing bug in Codex on AWS Bedrock is charging users approximately 10 times the expected rate. The issue was reported on GitHub and has generated significant discussion among developers.

Users of OpenAI's Codex model deployed through AWS Bedrock are experiencing severe overbilling due to a calculation error in the service's pricing mechanism. The bug causes charges to accumulate at roughly 10 times the advertised rate, affecting customers running production workloads. The issue was flagged in a GitHub issue that has drawn 128 points of community engagement and 40 comments, with developers sharing affected cases and workarounds. The problem appears to stem from incorrect token counting or rate application within the Bedrock integration. AWS and OpenAI have not yet issued an official statement regarding remediation or refunds for affected customers. Users are advised to monitor billing closely and consider disabling Codex usage on Bedrock until the issue is resolved. This incident highlights ongoing challenges with third-party AI API integrations and the importance of transparent billing mechanisms for cloud services.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A federal judge has overturned part of the conviction of former Google software engineer Linwei Ding, who was earlier found guilty of stealing AI trade secrets for two Chinese companies.

9H AGOAI Desk

Security researchers demonstrate how seemingly innocent interview questions can be weaponized to extract sensitive system information and compromise infrastructure. The technique exploits social engineering during technical assessments.

11H AGOIndustry Desk

Attackers hijacked the maintainer account of arrayref, a popular Rust crate, and injected infostealer malware that executed during code compilation. Developers using the poisoned version risked credential and data theft.

12H AGODev Desk

A threat actor impersonated a major cryptocurrency news outlet to target cybersecurity professionals. The attackers used Google Docs to distribute malware.

13H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.