A developer who runs a memory service for AI agents on Cloudflare Workers says one month of usage produced an invoice of about $36,000 for an application with 81 users, according to a post on the r/CloudFlare subreddit published around May 2026.

In Short

A programmer who built a small app that gives AI assistants a memory says a month of Cloudflare usage cost about $36,000, because bugs made the system repeat the same work again and again. It matters to anyone building products on pay-per-use cloud services, since every repeated action is metered and, by the poster's account, no hard spending limit exists. The poster says fixes are live and a request for relief is with Cloudflare, but the captured thread reports no decision.

What the post describes

According to the post, written by a Reddit user going by alameenswe, the product behind the invoice is RetainDB, which the author calls "a memory layer for AI agents". A client sends in a conversation; the service extracts structured memories, stores them and lets them be searched later. The stack combines Cloudflare Workers, KV (a key-value store), Durable Objects and Queues, and it had been "running fine for months" before the invoice arrived.

The exact publication day is not visible. The capture, taken in October 2026, labels the post as five months old, and a commenter cites a Cloudflare blog entry dated April 17, 2026, which places the thread after that date. This article therefore dates it to around May 2026.

The post lists four line items, reproduced below. The per-million rates are calculated from the post's own figures.

Line itemVolumeChargeImplied rate
KV write operations3.13 billion$15,635about $5.00 per million
KV read operations16.62 billion$8,306about $0.50 per million
Durable Object storage rows written4.01 billion$3,962about $0.99 per million
KV list operations574 million$2,870$5.00 per million

Against 81 users, the author arrived at "350,000 API requests per user per day" and first assumed a breach. A later calculation in the post put genuine traffic nearer 30,000 requests per user per day, amplified roughly tenfold by the defects described below. By the post's count, three of them compounded.

The three defects, as described

An internal call that re-queued itself

The write path ran as follows: a client calls /v1/memory, the request is queued, an ingest worker processes the queue message, and that worker calls /v1/memory internally to perform the write. The ingest worker forwarded the original request's write_mode, whose default is "async". The API worker therefore saw an asynchronous request, queued it again under a new job ID and returned HTTP 202, while the ingest worker marked its own job complete.

The cycle ended only when an idempotency key eventually deduplicated the content. By then, according to the post, each write had produced five to ten queue round trips and dozens of KV writes. The fix was a single line forcing write_mode: "sync" on internal calls. The author attributes about $15,000 to this defect.

Twelve Durable Object writes for every memory

A pending-overlay system issued unbatched storage.put() calls at each stage of a write. The post counts two calls for each of six events: enqueue in session scope, enqueue in user scope, job state set to processing, job state set to completed, and an acknowledgement in each scope. That makes twelve per memory write.

At 334 million memory writes a month, a figure the post says was inflated by the queue loop, twelve calls each gives about 4 billion Durable Object writes, matching the 4.01 billion on the invoice. The fix removed every Durable Object write from the ingest worker. The overlay carries a 30-second time to live, so it expires on its own; the acknowledgements were redundant, and the job-state mirror duplicated what KV already held. The count fell from twelve per write to two, an 83 per cent reduction. At the same volume that would be roughly 668 million writes. The post assigns about $4,000 to this defect.

An authentication fallback that scanned every key

API key authentication had three steps: a hash lookup (one KV read), a prefix lookup (one KV read) and, if both missed, a full kv.list() scan of all keys. Legacy keys lacked hash and prefix indexes, so the scan ran on 95 per cent of requests, according to the post. At $0.005 per 1,000 operations, 574 million scans cost $2,870. The fix was a flag, LEGACY_API_KEY_SCAN_ENABLED, set to "false". The post does not say whether the missing indexes for legacy keys were backfilled.

The author summarises the interaction plainly: "None of these bugs would have been catastrophic alone." The first multiplied every write by five to ten, the second multiplied Durable Object operations by twelve, and the third added a list scan to every request regardless.

Figures that do not reconcile

Several numbers in the post disagree with one another, and the thread does not resolve them.

The title says $36,000, the opening line says $35,000, and the four itemised charges sum to $30,773 by this publication's calculation. Between $4,200 and $5,200 is therefore unitemised. The title also refers to 16 billion Durable Object writes, yet the itemised Durable Object figure is 4.01 billion; the 16.62 billion figure belongs to KV reads. ServerlessHorrors, a site that catalogues billing incidents, lists the case with the same line items.

The request arithmetic is also loose. A load of 350,000 requests per user per day across 81 users implies about 850 million requests in 30 days, whereas 574 million scans at 95 per cent of requests implies roughly 604 million. And the per-defect dollar amounts ($15,000, $4,000 and $2,800) add up to about $21,800, leaving the $8,306 in KV reads unassigned to any defect.

An authorship dispute and a bot explanation

The comment section spent as much energy on the post's provenance as on its engineering. One commenter, tagged as a community MVP, wrote that "You're getting downvoted because of the AI-generated post." The author replied that Reddit had rejected an original draft and that Claude had been asked to produce a version suited to the forum. In reply to another commenter, the author also said the post was real and wrote that "this isn't a marketing strategy".

Scepticism extended to the code. Commenters pointed to the author's repositories as evidence of AI-assisted development. The author later conceded having lied about not using Claude Code "to avoid being roasted", said the tool had been used to tidy code during a rushed move from AWS, and added a claim of five years of coding experience. Another commenter argued that anyone testing the API call would have caught the loop; the author answered that the API had been tested heavily and the problem still slipped through. The author described the episode as "genuinely a skill issue".

An update posted in the thread shifts the causal story. Having reviewed the traffic, the author wrote that most requests came from bots. A rate limiter had been written but, by the author's account, never wired in during the migration; after switching on Cloudflare's own rate limiter, requests "dropped sharply". The defects, the author wrote, caused part of the problem "but majorly bots". The two accounts are not mutually exclusive, since each inbound bot request would pass through the same amplification paths, though the post does not quantify the split. Screenshots were offered as proof but are not part of the capture.

What the platform offers against runaway spend

The post's closing list of lessons includes a warning that "There's no hard spending cap on Workers." Another item reads "Set up Cloudflare spending alerts before you need them." The author says the first fact came to light through the invoice rather than an alert.

Cloudflare's own documentation draws a similar line between warning and stopping. According to Cloudflare's changelog, an entry dated April 13, 2026 added a Billable Usage dashboard showing daily charges, plus budget alerts keyed to dollar thresholds. The alerts are calculated daily from projected spend and fire once per billing cycle. A later changelog entrydated June 15, 2026 turned on a default $10 account-level alert for eligible pay-as-you-go accounts. According to that entry, the alert is informational only and does not cap usage, and because usage is processed once a day it fires the day after a threshold is crossed.

The thread's commenters pressed the same point. One wrote that letting a bill reach this size happened "without some sort of limit increase or some sort of anomaly detection". The author called a $5 plan that can run up such a charge "a foul play from their side", a view not shared by every participant; another commenter observed that the free tier would simply have stopped at its limit.

The case is not isolated. According to a PromptZone write-up published April 16, 2026, an undetected Durable Objects alarm loop produced a $34,000 bill in eight days with no active users. According to the Little Bear Apps blog, a loop in January 2026 turned a usual $5 monthly Cloudflare charge into $4,868 through 4.83 billion D1 database writes, with a peak of 1.42 billion on January 13.

Why this matters to the marketing community

Cloudflare has been courting developers who build agents. On April 7, 2025, it made Durable Objects available on its free tier, with 100,000 requests a day, 13,000 GB-seconds of daily compute and 5 GB of SQL storage, framed as a way to start agent projects with no commitment. The RetainDB thread shows the other side of that ladder: beyond the allowances, each operation is metered, and the meter does not stop on its own.

The product category is one marketers increasingly meet. Memory layers store what an assistant has learned about a user, and such layers sit behind personalisation, support and campaign tooling. A commenter in the thread observed that Cloudflare itself now sells such a service. The commenter quoted the sentence "The Session API provides the memory layer for agents built on the Cloudflare Agents SDK." According to Cloudflare's blog, Agent Memory entered private beta on April 17, 2026 as a managed service that extracts information from agent conversations, and each memory context maps to its own Durable Object instance.

Bot traffic is the second link. Cloudflare began offering publishers a way to block AI scrapers and crawlers in June 2024, then opened a private beta of pay per crawl on July 1, 2025, which answers crawler requests with an HTTP 402 payment-required response and a per-request price. Both address automated traffic as a cost borne by site operators. The RetainDB author's bot explanation puts a small developer in a similar position, paying per request for traffic that never was a customer. According to TechSpot, Cloudflare chief executive Matthew Prince said on June 3, 2026 that bots had overtaken human traffic on the company's network.

The scale mismatch is the most concrete point. By this publication's division of the invoice figures, the 3.13 billion KV writes equal about 39 million per user and the 16.62 billion reads about 205 million per user. On usage-priced infrastructure, cost tracks operations rather than customers, and a retry rule, an authentication fallback or an unbatched write changes the multiplier.

What is not established

The account rests on one post by its author. Cloudflare has not commented in the captured thread, no invoice or dashboard screenshots are included, and the amount actually charged, whether paid, disputed or credited, is not documented. In the author's words: "I don't know if Cloudflare will credit it." The inconsistencies set out above mean the specific figures are best treated as the author's claims, while the mechanisms described, a self-requeuing consumer, unbatched storage writes and a list-scan fallback, are internally coherent and match how the line items are priced.

Timeline

  • June 29, 2024 - Cloudflare's feature letting publishers block AI scrapers and crawlers is reported.
  • April 7, 2025 - Cloudflare makes Durable Objects available on its free tier during Developer Week.
  • July 1, 2025 - Cloudflare opens the pay per crawl private beta.
  • January 2026 - A separate developer's D1 write loop pushes a $5 monthly charge to $4,868, peaking at 1.42 billion writes on January 13, according to Little Bear Apps.
  • April 13, 2026 - Cloudflare adds a Billable Usage dashboard and budget alerts, according to its changelog.
  • April 16, 2026 - PromptZone publishes an account of a $34,000 Durable Objects bill over eight days.
  • April 17, 2026 - Cloudflare opens the Agent Memory private beta, according to its blog.
  • Around May 2026 - The RetainDB post appears on r/CloudFlare, describing a bill of about $36,000.
  • June 3, 2026 - Matthew Prince says bot traffic has passed human traffic on Cloudflare's network, according to TechSpot.
  • June 15, 2026 - Cloudflare turns on a default $10 informational budget alert for eligible pay-as-you-go accounts.
  • October 6, 2026 - Capture date of the thread; no credit decision is reported.

Summary

Who: A developer posting as alameenswe on the r/CloudFlare subreddit, behind RetainDB, a memory service for AI agents with 81 users, and Cloudflare, the infrastructure provider that issued the invoice.

What: A post claiming a usage invoice of about $36,000 for one month, attributed to a self-requeuing queue consumer, twelve unbatched Durable Object writes per memory write, and a KV list scan on 95 per cent of authentication requests, with an update blaming mostly bot traffic.

When: Published around May 2026, according to the thread's "five months ago" label as captured in October 2026; the exact day is not shown.

Where: On Cloudflare's developer platform (Workers, KV, Durable Objects, Queues), discussed on Reddit.

Why: The case shows how pay-per-operation pricing multiplies small defects into large invoices when no hard cap applies, and it arrives as AI-agent infrastructure and automated traffic grow on the same platforms marketers rely on. Cloudflare had not responded in the thread, and the figures are unverified.