How Cara Ran Up a $96,280 Vercel Bill in One Viral Week
- Platform
- Vercel
- When
- June 2024
- Bill
- $96,280
- Outcome
- Founder said she was working on the bill with Vercel; final settlement not publicly reported
In early June 2024, Cara, a portfolio and social app for artists, went viral and its usage-based Vercel bill grew by $96,280 in about a week. Founder Jingna Zhang shared the Vercel notification email on X, and Vercel's VP of product replied that the traffic looked legitimate and that the account had no spend limit turned on. Nearly all of the charge came from serverless function execution.
What happened
- Early June 2024: Artists unhappy with Meta's AI policies moved to Cara. TechCrunch reported growth from 40,000 to 650,000 users in about a week.
- June 3: Cara reached 300,000 users and crashed repeatedly, according to Silicon Republic. Function usage peaked at 56 million invocations that day as the Cara mobile app, which calls an API hosted on Vercel, climbed the App Store, per Vercel's Lee Robinson. He said Vercel also contacted the team directly that day.
- June 4: Zhang posted that Cara had passed 500,000 users.
- June 5 to 6: Zhang found the charge in her email on Wednesday, June 5, per TechCrunch, and posted a screenshot saying it did not match what her request logs showed. Robinson replied that the usage appeared valid, that the Firewall showed no malicious behavior, and that caching API responses could cut function usage considerably. He also wrote: "Looks like our systems have sent 12 notification emails to you." Zhang later said she had missed those emails while fixing outages.
- June 12: With Cara near 900,000 users, Zhang wrote that she was working on the bill with Vercel and optimizing the code.
Why the bill got so big
The screenshot was a daily usage notification, not a final invoice. It said the team had used 24,166% of its monthly included Serverless Function Execution, that this had added $96,280 to the bill so far, and that further usage would cost $40 per 100 GB-hours.
Under that model, Vercel bills function duration in GB-hours: the memory allocated to a function multiplied by the wall-clock time it runs, including time spent waiting on a database or another API. At $0.40 per GB-hour, $96,280 works out to about 240,700 GB-hours beyond the included amount. By our arithmetic, the 24,166% figure implies an allowance of roughly 1,000 GB-hours, which the traffic exceeded about 240 times over.
Cara's memory settings and response times were not published, but as an illustration, 56 million one-second invocations at 1 GB of memory come to about 15,600 GB-hours, or roughly $6,200 at that rate, in a single day.
The rate matters too. Vercel had announced new pricing in April 2024 that cut function duration from $0.40 to $0.18 per GB-hour and added $0.60 per million invocations, with existing Pro teams moving over on bills from late June. The rate in Cara's email matches the older price.
Nothing stopped the meter: Pro teams pay on-demand rates past the included usage, and Spend Management was opt-in. Robinson noted it was off, and that Zhang seemed to want the site to stay online.
Which number is right?
The screenshot shows $96,280 for function execution alone. Coverage described it differently: TechCrunch called it the cost for the last week, Silicon Republic called it an extra charge for exceeding the monthly allowance, a Hacker News submission called it one month of function spend, and InfoQ printed $98,280. An independent blogger was unsure when Cara's billing cycle started. Zhang herself later rounded it to almost $100,000 for six days, and then to $100,000 for one week of traffic.
How it ended
The final amount Cara paid has not been made public. Zhang said in June that she was working on the bill with Vercel. In a July 15 post on Cara's blog, she wrote that the team had spent the month since the surge optimizing code to reduce costs. She said hosting had cost about $2,000 a month before the surge and projected about $660,000 a year at the new traffic level. The post does not say whether the bill was paid in full, reduced or waived, and we found no Vercel statement on it.
Vercel changed its defaults afterward, though it did not tie the changes to Cara. On June 27, 2024, Spend Management began pausing production deployments by default when a team reaches its set amount. In September 2025, Vercel enabled it by default for new Pro teams, with a budget based on past usage, but deployments keep running unless you configure a hard limit.
How to protect yourself on Vercel
- Check your spend amount. In team Settings, then Billing, confirm Spend Management is on and set the On-Demand Budget to a number you can afford. It is available on Pro, and on Enterprise with Flexible Commitment.
- Decide whether to pause. A spend amount alone does not stop usage. Turn on Pause Production Deployments if you want a hard stop. Every project's production deployment then stops serving traffic, visitors see a 503 error, and you must resume each project by hand.
- Allow for lag. Vercel checks spend every few minutes, so set the amount below your true maximum.
- Route the alerts. Web and email notifications go out at 50%, 75% and 100% of the amount, with optional SMS at 100%. A webhook sends the same thresholds to your own endpoint.
- Cache function responses. Vercel's docs say
Cache-Controlheaders and CDN caching reduce invocations. This was Robinson's main suggestion for Cara. - Cap function duration. Set
maxDurationper function or per project. The default is 300 seconds; a short API route rarely needs that. - Know when Attack Mode helps. Attack Mode is free, and requests it blocks do not count toward usage. But it challenges visitors, and Vercel warns that standalone APIs and non-browser clients may be blocked. Cara's traffic was real users on a mobile app, so it would not have been the right tool.
What would have caught it sooner
Vercel did warn Cara, but the emails arrived while the founder was fighting outages. A hard cap would have taken the site offline during its biggest growth week, and viral traffic like this is often traffic you want to keep. What helps most in that spot is an alert that reaches the channel your team actually watches, early enough to add caching before the number gets large. CostHex reads usage every minute and alerts via Slack, Discord, Telegram or email with a link to the resource, and it is read-only by default. It currently supports Cloudflare Workers only. AWS and Firebase are next, and Vercel is planned for later but is not supported yet.
Sources
- Founder's post on X with the Vercel usage email screenshot, X (Jingna Zhang)
- Vercel VP of product reply on X, X (Lee Robinson)
- Founder's June 12 update on X, X (Jingna Zhang)
- Cara grew from 40k to 650k users in a week, TechCrunch
- Instagram rival Cara faces crashes and hefty bills from user surge, Silicon Republic
- Cara popularity led to substantial Vercel Functions expenses, InfoQ
- Finances and the Future of Cara (founder blog post), Cara
- A Look Into Cara (independent blog post), anderegg.ca
- Hacker News discussion, Hacker News
- Improved infrastructure pricing (April 2024), Vercel
- Legacy usage and pricing for Functions, Vercel Docs
- Spend Management, Vercel Docs
- Spend Management now pauses production deployments by default, Vercel Changelog
- Spend Management now enabled by default on Pro, Vercel Changelog
- Configuring maximum duration for Vercel Functions, Vercel Docs
- Attack Mode, Vercel Docs