You're not alone
jmail isn't the only project that got a surprise hosting bill. Here are real stories of developers who learned expensive lessons — so you don't have to. Numbers in these stories are approximate and based on public posts, talks, and blog write-ups — exact invoices are not public.
jmail.world: $46,000 on Vercel
The story that inspired this site. jmail.world was a temporary email service — a fun weekend project that went viral after being shared on social media. Hundreds of millions of pageviews (~450M by most estimates) in one month. The bill: $46,000.
What went wrong: No CDN in front of Vercel, so every request hit the origin. Unoptimized assets — a 650KB PNG Facebook icon served to every visitor. Aggressive hover-based prefetching generating 500 requests per minute per user.
Vercel Analytics at 100% sampling, creating a 'double dip' where you pay for analytics AND the edge requests analytics generates. Around 36% of the total bill went to analytics alone. The fix: Cloudflare in front, 30-day cache headers, SWR for archival content.
Vercel reportedly covered the bill — but it was described as a one-time courtesy.
Firebase Realtime DB: 'I left the listener open'
A developer built a chat app with Firebase Realtime Database. During testing, they attached a listener to the root of the database — effectively subscribing to every change in every chat room. Each message sent triggered a read event for every connected client.
With 500 concurrent users and messages flying, the read operations exploded exponentially. The monthly bill exceeded $30,000 in Firebase reads. The fix was simple: scope the listener to the specific chat room instead of the root node.
The lesson: in real-time databases, the scope of your listeners is directly proportional to your bill. Always subscribe to the narrowest data path possible.
AWS Lambda: $72,000 from a wrong configuration
An engineering team deployed a Lambda function that processed images. The function was triggered by S3 uploads. The problem: the processed images were saved back to the same S3 bucket, which triggered the Lambda again, which processed the image again, which saved it again — an infinite loop.
By the time someone noticed, the function had invoked itself millions of times. The bill: $72,000 in Lambda invocations and S3 operations. The fix: use a separate output bucket, or add a check for a metadata flag that marks files as already processed.
AWS eventually provided a credit, but not all providers are this generous.
Vercel + next-auth: $1,000+ for auth redirects
A developer using next-auth on Vercel discovered that authentication redirects were serverless function invocations. Every login, logout, and session check hit a serverless function. With a SaaS app doing frequent session checks (middleware on every route), the function invocations added up fast.
Thousands of users each generating 10-20 auth-related function invocations per session meant millions of invocations per month. The bill crossed $1,000 for what should have been a basic auth flow. The fix: move session checks to the client side where possible, use JWT instead of database sessions to avoid server lookups, and cache session data aggressively.
The pattern: it's always the same mistakes
Look at every horror story and you'll find the same root causes: Unbounded operations — listeners without scope, functions without termination conditions, prefetching without limits. Missing caching — every request hits the origin when a CDN could handle 95% of traffic. Wrong defaults — analytics at 100%, prefetch on viewport, SSR for static content.
No billing alerts — the first sign of trouble is the invoice, not a warning at $100. No load testing — nobody simulated viral traffic before it happened. These aren't exotic edge cases.
They're default configurations that work fine at small scale and explode at large scale.
What to learn from these stories
Set billing alerts from day one. Every cloud provider has them. Set thresholds at $100, $200, and $500.
Use a virtual card with spending limits for experimental projects. Test at scale before scale finds you. Use k6, Locust, or Artillery to simulate 10,000 concurrent users.
Watch what happens to your bill estimate. Audit your defaults. Is prefetching on? Is analytics sampling at 100%? Are your Lambda functions protected against loops? Is your database listener scoped correctly? Have an emergency plan.
Know how to flip your app to 'degraded mode' in 30 minutes: longer cache TTLs, disabled analytics, static fallback pages. You probably won't need it. But if you do, you'll be glad you prepared.
Want to see these principles in action?