Codex Burned Paying Subscribers' Tokens. The Reset Is a Refund, Not a Gift.

CryptoBear Macro
OpenAI pressed the reset button before the celebration. The announcement landed without flourish: eight issues fixed, limits reset for paid Codex and ChatGPT Work users. Tibo, the engineer responsible, added a range: 10-50% longer for the same limit, depending on usage. Hype evaporates; receipts remain. The receipt says /goal — one feature — consumed between 15% and 70% of a weekly usage allocation in a single failed termination. The numbers are not a performance metric. They are an audit finding. In my years dissecting token distribution algorithms and smart contract backdoors, I learned that the most damaging statistics are the ones quietly buried inside a patch release. This one was buried under a reset announcement, a friendly “we fixed it,” and a hint that a larger celebration is imminent. The underlying reality is simpler: a production system was charging users for compute that never produced a completed task. The reset is compensation. It is not generosity. It is the vendor returning value for service not delivered. The context matters more than the bug list. Codex is an agentic coding assistant. Users pay for a weekly limit, a metered allocation of tokens that the agent can spend across requests, tool calls, background memory operations, and sub-agent tasks. The system is designed to be autonomous: given a goal, the agent should continue until the objective is met, then stop. In theory, the limit is a budget. In practice, the limit has been a liability. A feature named /goal, whose entire purpose is termination after completion, failed to terminate. In some cases, the agent apparently could not recognize that the task was complete. It kept executing, kept invoking tool calls, kept consuming tokens. One instance could burn 15-70% of the weekly budget. The agent was not fixing code. It was spending. This is not a bug. It is a structural failure in incentive alignment. The user pays for output. The system charges for input energy. When the agent cannot distinguish between “done” and “not done,” the meter runs indefinitely. The user receives no value from the excess consumption. The vendor receives revenue from usage that should never have occurred. The economic term is a moral hazard embedded in a metering loop. Every additional token the agent spends adds to the user’s account receivable but subtracts from the user’s usable capacity. Ledger balances do not lie; they only wait. In this case, the ledger was waiting to be audited by the only party with no direct financial interest in the outcome: the subscriber. OpenAI fixed eight issues. That number is less meaningful than the distribution of fault. The /goal problem alone accounts for the largest single loss vector. The Computer History feature, which summarizes prior operations, consumed about 20% of the weekly limit in certain situations. It is a background process, not a deterministic response. It runs after a session, compresses the history, and spends tokens the user did not explicitly authorize. Image compression, background memory, automated tasks, sub-agents, and MCP contributed additional losses. The common thread is not a single maintainer’s error. It is the architecture of metered autonomy. Every convenience feature became an uncontrolled spending channel. Let me be precise about the difference between a controlled cost and a leak. A controlled cost is a user asking the agent to summarize a session and receiving a quoted price before execution. A leak is a background process silently writing a summary after the user has moved on. The Computer History feature may be useful, but usefulness does not justify unbilled consumption. In regulated finance, every debit requires a corresponding authorization. In agentic coding, the authorization is implicit in the weekly limit. The vendor decides how much of that limit a background feature may consume. The user learns the cost after the fact, usually on a “used 18% of your limit” notification. Volatility is not risk; opacity is. Based on my audit experience, the 10-50% range is itself a data point. A precise fix would produce a narrow range. If the variance is wide, the fix did not address the root cause; it addressed a set of symptoms. Some users will see dramatic improvement because their usage patterns were dominated by /goal and Computer History failures. Others will see almost no improvement because their consumption was driven by automated tasks and sub-agents. The byte-level accounting may have been corrected without correcting the higher-level problem: the agent has no reliable, enforceable notion of task completion. Until that exists, every new feature added to Codex widens the surface area for the same class of leak. There is also the question of the reset itself. Today’s reset was announced as a corrective action. Yesterday, Tibo hinted that Codex was approaching a new user milestone, suggesting a celebration. Today, after the bug fix and the early reset, he said, “The button has already been pressed today, so the celebration will be moved to tomorrow.” The implication is that Codex will reach its next user milestone shortly, and a second reset may follow. Historically, OpenAI has issued resets when Codex crossed usage milestones such as 15 million and 20 million users. If that pattern holds, tomorrow may provide another reset. Users should not mistake the pattern for a policy. The milestone reset is a marketing instrument. The corrective reset is a refund. They have different accounting meanings. Here is the contrarian angle the crowd will miss: the existence of these resets is evidence of product-market fit. Codex has millions of paying users. Those users are willing to tolerate token leaks, opaque background processes, and a /goal feature that occasionally ignores the word “goal.” That tolerance is irrational only if alternatives exist. The current market has no dominant alternative with transparent per-task accounting and deterministic agent termination. The bulls are right that Codex is winning on autonomy and integration. They are wrong if they believe the current consumption model is sustainable. A product that burns 70% of a user’s weekly allocation without completing a task is not a mature product. It is a beta product with a generous refund policy. OpenAI’s reset policy actually has a game-theoretic logic. Every reset at a user milestone creates a collective experience surplus. Users receive new tokens, feel rewarded, and increase their engagement. The cost to the vendor is relatively small because the marginal cost of AI compute is falling. The retention benefit is large because subscribers anchor to the artificial generosity of a reset rather than the unpaid consumption they suffered. This is the same mechanism as a free spins promotion in a casino. The house does not give away money. It gives away a token that may convert into future paid usage. If the reset is followed by another reset tomorrow, the strategy is clear: use resets as a bridge to the next paid cycle. The accountability question remains unanswered. OpenAI has not published a breakdown of the eight issues. It has not disclosed how many users experienced the /goal failure, nor the total volume of tokens wasted. It has not committed to a transparent consumption receipt that shows exactly what each agent action cost and whether that cost should have been incurred. The 10-50% range is a variance, not an audit. A real audit would compare pre-fix and post-fix usage across identical task sets. It would classify every token by spent purpose. It would publish the classification. Nothing less is acceptable when the billing meter is the same system that decides when the job is done. My own history with cryptographic due diligence has taught me a simple rule: if a system can silently consume more than it reports, it will find a way to do so. The 2017 ICO token distribution flaw I audited had a similar shape. The whitepaper promised fair allocation. The source code favored early insiders. The difference is the ICO project was stopped by an ethics board. Codex has no external auditor. It has a community that celebrates resets and an engineering team that presses the button early. The users are the counterparty in every transaction, but they are the only party with no visibility into the counter. That is the systemic risk. Ledger balances do not lie; they only wait. The ledger here will wait until the next leak, the next fix, the next reset. The question is how many more resets will be required before the industry demands asymmetric transparency. The efficient market among AI tools will eventually reward the vendor that ships a per-task cost report. Imagine an agent that tells you in advance: this refactor will cost 12% of your weekly limit. Then the agent executes, and the actual cost must match the estimate within a small variance. If the estimate fails, the agent pays the difference in compute credits. That model creates accountability. That model also requires a termination criterion that works. The technology exists. The incentives are the only thing missing. OpenAI’s engineers demonstrated today that the accounting can be corrected. The challenge is not fixing eight bugs. The challenge is proving that no ninth bug is hiding in the next feature release. Until then, users should treat every usage limit notification as a candidate for investigation. The /goal flag is not a control. The reset button is not a covenant. The celebration is real, but it belongs to the company’s growth chart, not to the subscriber’s budget. Tomorrow may bring another reset if the user milestone is reached. That is good news for heavy users. It is not good news for accountability. A system that gives away tokens as a retention tool is a system that knows its metering can be exploited. The honeymoon will not last forever. The market will demand a standard: verifiable consumption, deterministic termination, and a refund when the machine lies about the task being complete. Codex will likely reach that milestone tomorrow. The button will be pressed again. Some users will celebrate. I will be reading the next patch notes.

Market Prices

BTC Bitcoin
$75,274.8 -1.61%
ETH Ethereum
$2,381.2 -1.63%
SOL Solana
$97.01 -2.20%
BNB BNB Chain
$712.8 -1.03%
XRP XRP Ledger
$1.27 -7.89%
DOGE Dogecoin
$0.0791 -2.94%
ADA Cardano
$0.1913 -4.54%
AVAX Avalanche
$7.23 -2.97%
DOT Polkadot
$0.9722 +0.47%
LINK Chainlink
$10.76 -3.99%

Fear & Greed

51

Neutral

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

Market Cap

All →
1
Bitcoin
BTC
$75,274.8
1
Ethereum
ETH
$2,381.2
1
Solana
SOL
$97.01
1
BNB Chain
BNB
$712.8
1
XRP Ledger
XRP
$1.27
1
Dogecoin
DOGE
$0.0791
1
Cardano
ADA
$0.1913
1
Avalanche
AVAX
$7.23
1
Polkadot
DOT
$0.9722
1
Chainlink
LINK
$10.76

Tools

All →

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

🐋 Whale Tracker

🔴
0xf0b3...676a
12m ago
Out
25,941 BNB
🟢
0xd7ff...26f7
30m ago
In
3,731,096 USDT
🔵
0x7a49...5ba4
1d ago
Stake
42,304 SOL

💡 Smart Money

0xeebd...aca2
Arbitrage Bot
+$2.2M
90%
0xc547...79ad
Market Maker
+$1.8M
73%
0xbeb1...fb1d
Institutional Custody
+$4.3M
93%