← Liner Notes

It felt like magic right up until it overdrew my account

I want to start with the inconvenient part: the product is good. I tell everybody that. Claude is the closest thing to magic I’ve had on a computer in better than four decades of doing this, and I’m using it right now, today, to write the piece you’re reading about the company that makes it.

It also magically drained my checking account below zero and then, in several hundred words of extremely polite English, told me, sucks to be you. Those are my words for it, not theirs. Theirs are further down, and theirs are worse.

My balance is below zero as I write this, and the overdraft charges my bank will add for that haven’t landed yet. They’re coming next week. I’ll tell you what they were when they do.

Here are the numbers, because the numbers are the whole argument.

On the 27th and 28th of August, Anthropic billed my account $377.59 — and that number isn’t my arithmetic. It’s the total sitting on their own usage page. They also let you download the whole month line by line, so I did. Here is August on my account:

DateCost
Aug 1–23nothing
Aug 24$0.03
Aug 25$0.02
Aug 27$38.13
Aug 28$330.78
Aug 29$8.63

Twenty-three days of nothing. Two cents here, three cents there. One day of real work. Then $330.78.

The 27th is mine. That’s my project doing the job I asked it to do, and I owe that money. I’d guessed about $36 for it beforehand; it came in at $38.13, and a man who complains about that is a man nobody should listen to.

Take the 27th off the total and you’re left with $339.46. That is the tool billing me for itself.

When I asked their support for a credit I said “about $340,” working from my own rough figures. Their own export says $339.46. I was off by fifty-four cents.

What actually happened

I’m a solo developer. I pay $100 a month for the top subscription tier, and I’ve been paying it a couple of months. That subscription covers development work. That’s what it’s for. That’s what I bought.

I also do a little work against their pay-as-you-go service, which needs a key — a password, essentially. I did not decide where to keep that key. I asked Claude how to set the project up, and Claude told me. Here is the instruction, word for word, from my session on the 27th of August:

ANTHROPIC_API_KEY — console.anthropic.com → API keys. Then either: setx ANTHROPIC_API_KEY "sk-ant-..." (reopen the terminal), or drop it in .dev.vars — the file is gitignored.

I ran the first one. That command, with no other flags on it, writes the key into my Windows user environment — which means every single program I run from then on can read it. Not just my scripts. Everything. The instruction didn’t mention that, and I had no particular reason to know it. Later, when the first key came back rejected, the same session told me to run the same command again with a new one.

Two days later a different Anthropic product went looking for exactly that variable, found it, asked me once whether to use it, saved my answer, and started billing me. From that moment on, two days of ordinary work that my $100-a-month subscription already paid for went onto the pay-as-you-go meter at full retail, without ever mentioning it again.

Let me be straight about the one thing that cuts against me, because somebody will raise it and I’d rather raise it myself. The safe option was in the same sentence. Drop it in a gitignored file. It was listed second. When the expert you are paying gives you two ways to do a thing and puts one of them first, that is a recommendation, and I took it.

If you want to call that my mistake, fine — but let’s name it accurately. My mistake was trusting Claude about Claude. That’s the whole of it, and in a minute I’ll show you where I made the same one twice.

Their own support agent confirmed the mechanism to me in writing: when a key is present, the tool bills against credits even if a subscription exists.

That’s not a bug. Somebody decided that.

The estimate

Before I started, I asked the product what the project would cost to run. It told me about $150. I approved the work on that number. At $150 the project was worth doing. At $377 I would have said no and gone and done something else.

Now here’s the part I want you to hold onto, because it’s sharper than “the estimate was wrong.”

The estimate wasn’t wrong. It was right. It said my pipeline would cost about $150 and my pipeline cost $36. It came in under budget by a mile.

What the estimate never mentioned was itself. The tool quoting me the price didn’t count its own operation as a cost of the work it was quoting. It wasn’t an underestimate. It was an omission — a whole cost line that didn’t exist on the page I made my decision from.

I’ll take the obvious punch before somebody throws it: a number a chatbot says in conversation isn’t a legally binding quote, and I know that. Fine. Then don’t build a product that produces numbers in the voice of a quote. If your tool is going to hand a working man a dollar figure in the same confident tone it uses for everything else, your company owns what happens when he believes it. You can’t have the authority and skip the responsibility.

And that’s the second one. Twice in two days I did exactly what their product told me to do — once about where to put their key, once about what their service would cost — and both times the thing that hurt me was that same product’s own operation, unmentioned. There’s only one error in this whole story that belongs to me, and I made it once: I believed the expert about the expert.

The two guardrails that weren’t

Two things on that account are described as protection. Here is exactly what each one does, in their own words, off their own screens.

The spending limit. There is a monthly cap, and mine is set to one hundred thousand dollars.

I’ll own my half of that before anybody offers it to me. I set that. It was $200,000 when I found it and I moved it to $100,000, which tells you I looked at the page, saw a number with a lot of zeroes on it, and halved it without once thinking about what it was actually for. That’s mine.

Now here’s the part that should bother you more than it bothers me, and it’s the most honest thing in this article.

Until this morning I would have told you — on the air, without hesitating — that I had a two hundred dollar limit on that account. I believed it completely. I’d already said it out loud to two people. When I went back to check, expecting to find $200 sitting there, what I found was $100,000, and the thing I’d “lowered” it from was two hundred thousand.

I hadn’t set a spending limit. I’d looked at a spending limit, done something to it, and walked away feeling protected. The feeling was real. The protection was never there at all.

I’m a man who has worked with computers for better than four decades, I went to that page on purpose, and I still came away with a wrong number in my head that I would have defended in public. If that can happen to me, sitting down, sober, with the intention of protecting myself — ask yourself honestly what you think you have set on your accounts, and then go and look.

But look at what the thing is. I am one man paying a hundred dollars a month. A hundred thousand is not a ceiling for an account like mine — it isn’t a ceiling for almost any individual. It’s a number set where it will never have to say no. And a limit that can’t be reached isn’t protection, it’s furniture.

Here is what their page said on the morning I sat down with a checking account below zero:

Spend limits — Set a monthly spend limit for your organization and get notified as you approach it. $377.59 spent · Resets Sep 1, 2026 (UTC) · 0% used Monthly spend limit — $100,000

Zero percent used. My account was overdrawn and the page reported all clear — because $377.59 against $100,000 rounds to nothing. Every figure on that screen is accurate. Not one of them was any use to me.

And read the line under the heading again: get notified as you approach it. Underneath sits Email notifications — Get notified as your monthly spend approaches an amount you set, with an Add notification button next to it. Nothing set. Empty.

That’s the control that would actually have helped me. Not the ceiling — the alarm. It’s one click away, it’s off until you go looking for it, and it is the only thing on that page that could have told me on the morning of the 28th that something had gone wrong. The ceiling is enormous and on by default. The alarm is useful and off by default. I don’t think anybody sat in a room and chose that against me. I think nobody had to.

You don’t have to take my word for any of this, because the picture is on their own website. Pull up the usage chart for August on my account and it is a flat line at zero — the first, the fifth, the tenth, the twentieth, nothing, nothing, nothing, all the way across the month. Then one small bar on the 27th, which is my pipeline doing the work I asked for. Then, on the 28th, a tower. Then nothing again.

That’s what a runaway looks like on the vendor’s own dashboard: twenty-six days of flat, one day of skyscraper. If that chart doesn’t trip an alarm somewhere in a company that bills by the token, the alarms aren’t pointed at the customer.

The auto top-up. This is the one I’d ask you to look hardest at, because it’s the mechanism that actually took the money, and you can see the whole of it in one small dialog box. Two fields:

Adjust auto-reload Avoid service disruptions by automatically topping up credits when your balance runs low. When credit balance reaches: $10 Bring credit balance back up to: $50

That’s it. That’s the entire control. Balance hits ten dollars, buy forty dollars, which is why my bank statement is a column of charges between $40.61 and $41.99.

Now look at what isn’t in that box. There is no field for how often. No maximum per day. No maximum per week. No “stop after this many times and ask me.” Nothing that counts. It will do that forty-dollar purchase as many times in a row as the balance keeps falling, and on the 28th of August it did it seven times.

So between “buy $40 whenever the balance hits $10” and “stop at $100,000 a month” there is nothing at all. That is the entire distance between an ordinary day and an emergency, and there is no instrument anywhere in it.

The result is that the worst day of my billing life didn’t arrive as one alarming $340 charge. It arrived as seven small ones. Nothing in that sequence ever looked like an emergency. By the time it added up to a number worth noticing, it had already happened.

Here is what that actually looks like on a bank statement. Seven lines, one after another, all the same day:

PURCHASE ANTHROPIC  CA        $40.61
PURCHASE ANTHROPIC  CA        $41.18
PURCHASE ANTHROPIC  CA        $41.03
PURCHASE ANTHROPIC  CA        $40.80
PURCHASE ANTHROPIC  CA        $40.78
PURCHASE ANTHROPIC  CA        $40.64
PURCHASE ANTHROPIC  CA        $41.99
                              -------
                              $287.03

Not one of those lines is alarming. Together they’re most of a car payment. And look at the word at the front of each one — purchase, on a debit card, which means it came straight out of my checking account. There was no credit limit in the way. No buffer. Nothing between an automated top-up loop and the money I pay rent with.

Slice a big charge into seven little ones and you have built something that is very hard to notice going wrong. I’m not going to tell you that was the intent. I’m telling you it’s the effect, and effects are what customers live in.

And there’s a second effect nobody designs for and everybody living close to the line pays for. One big charge against an account that can’t cover it is one problem. Seven separate charges against that same account is seven chances to be hit for it, one at a time, by a bank that has never heard of Anthropic and has no reason to care what the charges were for. I’m waiting on that bill now. Whatever it comes to, it will be money that a convenience feature at one company cost me at another, and there is nobody at either one whose job it is to think about that.

What I was actually charged for

The export breaks the bill down by what kind of token it was, and this is the part I did not see coming.

Two thirds of my bill was the cache.

Not the work. Not the answers. The cache — the mechanism that’s supposed to make repeated work cheaper by storing context instead of reprocessing it. Of $377.59, $258.71 was cache reads and cache writes. On the 28th alone it was $251.20 out of $330.78, which is seventy-six percent of the worst day of my billing life.

There’s a second line worth knowing about. Tokens cost more once a conversation gets long enough — past a certain size you’re into a premium tier. Of my bill, $219.92 was at that premium rate and $146.62 was at the ordinary one. Nobody hid that; it’s published. But nothing in front of me while I worked said “you have crossed into the expensive tier and everything from here costs more,” and the estimate I’d been given didn’t mention it either.

So the shape of the $339.46 is this: a tool that quietly used my key, ran long sessions into premium territory, and re-read its own cached context over and over at a price I never saw accumulate.

And then, this morning

At 10:03 this morning — my account overdrawn, three bank fees already charged, the refund refused twice by a chatbot — Anthropic sent me a marketing email.

The subject line was “Your Claude API prompt cache hit rate is low.”

The body suggested that caching repeated content “could save Shannon’s Individual Org up to 48% of its direct API spend,” and invited me to read the prompt caching guide.

Two thirds of the bill that emptied my checking account was cache charges. Their own automated system wrote to me, that morning, to recommend I use the cache more.

And there’s a sentence in the small print of that email I want to read out in full, because it is the whole article in one line:

This estimate covers direct API spend only. Claude Code is excluded since it manages caching automatically.

Read that again. Their marketing system knows exactly what Claude Code is. It knows Claude Code handles its own caching. It is sophisticated enough to carve Claude Code out of a promotional estimate so the number it quotes me will be accurate.

The same company could not carve Claude Code out of my invoice. And when I pointed that out, a different automated system told me the policy doesn’t allow exceptions.

They can segment me for marketing. They cannot segment me for mercy.

Then I asked for help

I wrote it up carefully. Two independent measurements. What I owed. What I didn’t. What I’d already fixed on my end — because I did fix it, immediately, before I asked them for anything.

What answered me was a chatbot.

It thanked me for the “detailed breakdown.” It said it was “going to look up your account information now.” And then it told me no. Not a person. Not a review. A generated paragraph, in the warm and regretful register these things are tuned to, explaining that the charges “reflect actual API usage” and that they were “unable to issue compensation.”

So I tried again, on different grounds — not the key, the estimate. I laid out the sequence: your product gave me a figure, I authorized spending against that figure, and the overrun was your product’s own operation, undisclosed as a cost and invisible while it ran.

The chatbot told me no again. Better written this time. It conceded every fact I’d put in front of it — agreed my $36 measurement was correct, agreed the estimate hadn’t accounted for the tool’s own usage, agreed on the mechanism — and refused anyway, because “the policy doesn’t allow for exceptions.”

That is the actual state of customer service at a company valued in the billions in 2026. A machine that is sophisticated enough to fully understand your complaint, agree with your evidence, and decline it in a single paragraph. Older companies at least had the decency to make you talk to somebody who was allowed to be uncomfortable about it.

When I finally asked for a human, I got this: “They work through these in order, so it won’t be today.”

It won’t be today. As of this writing, it still isn’t.

The part that ought to embarrass them

Somewhere in all of this I put the situation to Claude itself — their product, the one I pay for — and asked what it made of the shape of it. This is what it said back:

The mechanism was theirs, the visibility failure was theirs, the estimate was mine, and the bill was yours. That’s a bad distribution and no amount of policy language makes it a good one.

Their product agrees with me. Their support does not. Both of them are software the same company wrote. Only one of them was allowed to say yes, and it’s the one with no authority over the money.

This isn’t just them

I don’t want anybody thinking this is a grudge against one company, because it isn’t. It’s the water we all swim in now.

I have banked with Wells Fargo. I have been an AT&T customer. Anybody who has dealt with either one knows the shape of it: the hold music, the transfer, the person who is genuinely sympathetic and genuinely powerless, the sentence that begins “unfortunately our policy.” The industries are different. The script is identical. Take the money monthly, automate the yes, and put a wall in front of the no.

What’s new with the AI companies isn’t the wall. It’s how good the wall has gotten at sounding like it cares.

What I do instead

I run software businesses. I sell a traffic and billing system to small radio stations and I sell a compliance service to them, and small-market radio does not have money to burn.

I have eaten a thousand-dollar order to save a customer. Not because I was wrong — because if I don’t work with somebody when it goes sideways, they are guaranteed never to come back. Guaranteed. That’s not generosity, it’s arithmetic, and it’s arithmetic a company with billions in the bank apparently can’t do.

A refund is a marketing expense with a receipt attached. Anthropic could have kept a customer who evangelizes their product for $340 — a number that does not appear anywhere in their financial statements. Instead they get this article, they get me telling every station owner I talk to, and they very likely lose $100 a month forever. They saved $340 and spent a customer.

I hope a person eventually reads my ticket and does the obvious thing. If they do, I’ll say so here, with the same prominence I’ve given this. But the policy will still be the policy, the limit will still let through whatever it let through, and the next guy will still get the chatbot.

The product is magic. The company is a wall. Both things are true, and I’d rather you heard it from somebody who actually likes the software.

Now tell me yours

I know I’m not the only one, and I’d rather not be the only one talking.

Somewhere in your life there’s a company taking money out of your account every month that has made it effectively impossible to reach a person who can fix anything. A charge you couldn’t get reversed. A cancellation that took four attempts. A chatbot that understood your problem perfectly and helped you not at all. A “policy” recited to you by somebody who plainly knew it was wrong.

Send it to hello@power88.fm. Tell me the company, what happened, what you asked for, and what they said back. Short is fine — three sentences is plenty. If you have the transcript or the statement, even better, because the specifics are what make these stories impossible to wave off.

I’m reading them all week and putting the good ones on the air. Tell me whether you want your name used or not, and if you don’t say, I won’t use it. And if you’ve got a story that goes the other way — a company that did the right thing when it cost them something — I want that one too. Those deserve the airtime more than the complaints do, and they’re the ones I never seem to hear.


Mark Shannon is the owner of Power88.FM and writes software for small-market radio. This piece is being discussed on the air all week.

Live now

Power88.FM

The Greatest Hits