Hi everyone,
I’m writing this out of sheer frustration because my business operations have been completely frozen for 3 weeks, and OpenAI Support has gone entirely radio silent on a massive billing security issue.
On June 15, my account was compromised. A hacker managed to leak an API key (sk-.) and immediately hooked it up to an automated data-scraping script.
Here is where OpenAI’s infrastructure failed spectacularly:
My monthly Hard Limit was strictly set to $600.
Within just 34 minutes, the attacker flooded the API with parallel high-volume gpt-5.5 reasoning requests.
The billing system lagged so badly that I received the 50% alert ($300) and the 100% alert ($600) at the exact same minute (20:59).
By the time OpenAI’s system finally triggered the hard limit block, the hacker had racked up till $2К in debt.
I did exactly what any responsible developer would do: I instantly revoked all keys, secured the account, removed my credit card to prevent direct theft, and submitted an urgent ticket on June 16 (https://help.openai.com/).
The bot escalated it to a “support specialist,” and since then… nothing. It has been 20 days of absolute silence. No emails, no human responses in the Help Center, nothing but a broken workflow.
Has anyone else experienced such an extreme delay when dealing with unauthorized limit bypasses? How do you actually get a human from the Billing / Trust & Safety team to look at a ticket when $2,000 is on the line?
Any advice or staff visibility on this would be highly appreciated.