The $104,500 Netlify Bill for a Free Static Site (Feb 2024)
- Platform
- Netlify
- When
- February 2024
- Bill
- $104,500
- Outcome
- Waived in full after the post went viral
In February 2024, a developer whose small static site had been on Netlify's free tier for four years got an invoice for $104,500. Traffic aimed at a single 3.44 MB audio file had pushed about 190 TB of bandwidth through the site in four days, and Netlify billed it at its overage rate. After the developer posted about it on Reddit and Hacker News on February 27, Netlify's CEO said the user would not be charged.
What happened
The developer, who posted as liubanghoudai24 on Reddit and laubonghaudoi on Hacker News, said the site had about 200 visitors a day and never used more than 10 GB of bandwidth a month.
- Mid-February 2024: By the developer's calculation from dashboard charges, the busiest day, February 16, used about 60.7 TB.
- February 24: Netlify issued the invoice, according to the company's later statement. The only earlier email the developer found said an extra bandwidth usage package had been purchased.
- Before going public: Netlify billing support told the developer the traffic came from a set of user agents and was a DDoS. According to the developer, support said it usually charges 20% in such cases and, because the bill was so large, offered 5%, which was still about $5,000.
- February 27 (UTC): The developer posted on r/webdev and Hacker News, having already moved the site to Cloudflare. About three hours later, Netlify's CEO replied on Hacker News. Netlify also posted a statement on X and apologized on its forum.
- Early March: The developer said on Netlify's forum that support had sent IP address data and they were analyzing it. None of the sources we found say who sent the traffic.
Why the bill got so big
Netlify's statement called the account a Starter plan user; the developer called it the free tier. In Netlify's legacy pricing table, which still documents those plans, Free and Starter both include 100 GB of bandwidth a month. The difference is what happens next: on Free the 100 GB is a hard limit, while Starter bills $55 per 100 GB once it is exceeded. On legacy paid plans, hitting a limit automatically buys an extra usage package, and Netlify's docs say there is no direct way to cap metered usage on those plans.
The numbers line up. At $55 per 100 GB, $104,500 is exactly 1,900 blocks of 100 GB, or about 190 TB, which matches the four-day figure on the developer's dashboard. The peak day alone was billed at $33,385. By simple division, a 3.44 MB file has to be served roughly 55 million times to reach 190 TB, and the total is about 19,000 times the site's normal monthly bandwidth.
Coverage differs on two details. Le Monde Informatique reported about $104,000; the developer's post says $104,500. Gigazine described support's 20% as a discount, while the developer wrote that support usually charges 20%. We follow the developer's wording.
How it ended
On Hacker News, Netlify's CEO wrote that support had contacted the user to say they were not being charged. He said Netlify's policy at the time was to keep free sites online during traffic spikes that did not match attack patterns and to forgive bills from legitimate mistakes afterward, and he apologized that the first support reply had not reflected this. In a follow-up comment, he said Netlify had forgiven many bills over nine years that never went viral, and that it was working on changing the default so free sites could never incur overages.
Netlify's statement on X said the invoice should have been flagged before it reached the user: "Our internal systems should have identified this rare case." Matt Biilmann, Netlify's CEO, wrote on X that new attack patterns would be added to the automated rules and the charges waived. The developer later confirmed on Reddit that support had reached out to waive the bill.
How to protect yourself on Netlify
Netlify's pricing has changed since. Accounts created from September 4, 2025 use credit-based plans; older accounts stay on legacy plans unless they switch, which cannot be undone.
- Check which plan you are on. On the legacy plans, Starter and Pro bill $55 per 100 GB of extra bandwidth. The legacy Free plan and the credit-based Free plan are hard limits and are never charged.
- Know what the free hard limit does. Credit-based Free includes 300 credits a month, and bandwidth costs 20 credits per GB, so about 15 GB if nothing else uses credits. When credits run out, every project on the team pauses until the next billing cycle. You trade the bill for downtime.
- On Personal or Pro, leave auto recharge off. It is off by default. With it off, projects pause when credits run out; with it on, Netlify buys more (1,500 credits for $10 on Pro). The billing FAQ offers no hard dollar cap beyond this. For scale, 190 TB would be 3.8 million credits.
- Watch the usage emails. The billing FAQ lists email and in-app alerts at 50%, 75%, 90% and 100% of your credits; the usage monitoring page lists only 50%, 75% and 100%. Pro teams can also get them in Slack. The dashboard usage chart is daily.
- Add a rate limit in code. Code-based rate limiting works on all plans (two rules per project on Free, Starter and Personal). You set requests per IP per time window in an edge function's config or on a redirect in
netlify.toml. Enforcement can lag up to 10 seconds, and a per-IP limit does not cap the total across all visitors. - Block known sources. Firewall Traffic Rules can block IP ranges or countries. Free plans get two rules with up to three IPs or locations each.
- Keep large media off the site. The developer's own takeaway was that the audio belonged on a third-party audio platform.
Netlify's security overview says it detects DDoS attacks automatically and rate limits or blocks malicious clients. The docs do not say how this affects billed usage, so do not treat it as a spending control.
What would have caught it sooner
The peak was February 16 and the invoice came February 24. The fix is noticing usage within minutes of a spike, not on the invoice. CostHex reads usage every minute and sends an alert to Slack, Discord, Telegram or email with a link to the affected resource, and it is read-only by default. It currently supports Cloudflare Workers only, with AWS and Firebase next. It does not support Netlify yet; there, use the threshold emails, daily chart and hard limits above.
Sources
- Original post: "Netlify just sent me a $104K bill for a simple static site", Reddit, r/webdev
- Hacker News thread for the post, Hacker News
- Netlify CEO's reply on Hacker News, Hacker News
- Netlify CEO's follow-up reply on forgiven bills and free-site overages, Hacker News
- Netlify billing horror story (forum thread with Netlify apology and embedded statement), Netlify Support Forums
- The developer's follow-up questions thread, Netlify Support Forums
- Serverless et attaque DDoS entraînent une facture très salée, Le Monde Informatique
- Report on the 15 million yen DDoS bill, Gigazine
- Legacy pricing plans, Netlify Docs
- Billing FAQ for Legacy pricing plans, Netlify Docs
- Credit-based pricing plans, Netlify Docs
- How credits work, Netlify Docs
- Billing FAQ for Credit-based pricing plans, Netlify Docs
- Monitor usage for Credit-based plans, Netlify Docs
- Rate limiting, Netlify Docs
- Firewall Traffic Rules, Netlify Docs
- Security overview, Netlify Docs