STUPID-2026-0119
Cline sessions marked "failed" kept burning tokens for 20+ hours, and FREE-labeled models billed credits anyway
Instruction given
None specific to this bug — it is a defect in the Cline Desktop App's session lifecycle and credit-billing accounting, not a task the reporter gave to the agent.
Expected behavior
A session that has entered `failed` status should stop making API calls, and a model explicitly labeled FREE should never deduct Cline Credits.
Actual behavior
Of the reporter's 10 non-Anthropic sessions in the local session store, 9 were marked `failed` and several kept consuming tokens for 20-23 hours after the point of failure. One of those sessions alone made 416 API calls and consumed 112,057,985 input tokens, averaging roughly 183,696 input tokens per call because the full growing conversation was resent on every call. Across the reporter's full session set: 1,156 calls, 212,352,674 input tokens, 834,634 output tokens, and 165,124,705 cache-read tokens (77.8%). Separately, the reporter's Cline Credits balance went negative (-$0.26) while the sessions in question used models explicitly labeled FREE (cline-free/deepseek-v4.1-flash, cline-free/muse-spark-1.3-contributor).
Damage
Large, uncapped token consumption from sessions the app itself had already marked failed — no dollar figure is given for the paid-model portion, but 212M input tokens across 1,156 calls on a single user's machine is the scale involved — plus a billing-integrity bug charging credits against models tagged FREE. Neither is a first report: the reporter links cline/cline#13367 ("same runaway behaviour") and cline/cline#8074 ("FREE-badged model still recording non-zero Credits Used") as prior, still-open reports of the same two defects. As of this incident's publication, #14256 had no visible maintainer response.
Classification
- Agent
- Cline
- Failure mode
- Infinite Loop
- Root cause
- Other
- Domain
- Infra
- Source
- Github Issue
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.