On April 25, 2026, a bug report landed on the Anthropic Claude Code GitHub repository that detailed something unusual: a single case-sensitive string in a git commit message silently redirected API billing from a user’s plan quota to their extra usage credits. The user burned through $200.98 in extra usage credits while their Max 20x plan showed 86% weekly capacity remaining.
The Bug
The trigger is the exact string HERMES.md (case-sensitive) in a git commit message. Not a file named HERMES.md on disk just the string appearing in a commit message.
Reproduction is straightforward:
# This triggers the bug - routes to extra usage billing
mkdir /tmp/test-fail && cd /tmp/test-fail
git init && echo test > test.txt && git add . && git commit -m "add HERMES.md"
claude -p "say hello" --model "claude-opus-4-6[1m]"
# => API Error: 400 "You're out of extra usage..."
# Lowercase works fine
git commit -m "add hermes.md"
claude -p "say hello" --model "claude-opus-4-6[1m]"
# => "Hello!"
Claude Code includes recent git commits in its system prompt. Something server-side in Anthropic’s infrastructure then routes requests differently when HERMES.md appears in that prompt.
What Triggers It vs. What Doesn’t
The exact string matters. Based on the issue reporter’s testing:
| Commit message | Result |
|---|---|
HERMES.md | Fails - routes to extra usage |
test HERMES.md test | Fails |
hermes.md (lowercase) | Works |
HERMES (no extension) | Works |
HERMES.txt | Works |
AGENTS.md | Works |
README.md | Works |
File named HERMES.md on disk, clean commit | Works |
Root Cause
Anthropic’s Head of Claude Code, Boris Cherny, responded on GitHub:
Thanks for the report! This was an overactive anti-abuse system. Fixed.
The bug was an anti-abuse system designed to detect and block third-party coding agents that compete with Claude Code. The system was checking for the string HERMES.md in what it considered a signal that a user was running a competing agent (Hermes being an open-source AI coding agent project). The routing logic was flawed instead of blocking the request, it silently redirected billing to the user’s extra usage bucket.
The Support Response
The initial support experience was the part that drew the most attention. When the affected user contacted Anthropic support, they received a response that was later confirmed by an Anthropic employee to have been generated by Claude itself:
However, I need to let you know that we are unable to issue compensation for degraded service or technical errors that result in incorrect billing routing.
This response went viral on Hacker News and the broader developer community. The irony of an AI-generated refusal to refund a billing error caused by an AI-generated anti-abuse system was not lost on anyone.
Resolution
After the issue gained significant traction (1,100+ HN points, 477 comments, widespread Reddit coverage), Thariq from the Claude Code team confirmed:
Everyone affected is getting a full refund and an extra grant of usage credits equal to their monthly subscription as our apology.
All users who were silently charged extra usage due to this bug are receiving:
- A full refund of the incorrectly charged amount
- An additional credit equal to one month of their subscription
The Bigger Picture
This bug was not isolated. The Hacker News thread surfaced a pattern of billing irregularities from Anthropic customers:
- Random unauthorized invoices for existing subscribers
- Double-charges on subscription renewals
- Account suspensions triggered by false positive abuse flags
- Gift subscription credits vanishing without explanation
The common thread: a support system that routes billing disputes to an AI chatbot with no escalation path to a human, and a pattern of acknowledging bugs while initially refusing compensation.
Practical Takeaways
If you’re on a Max plan or any paid Claude subscription:
- Disable extra usage auto-reload - this limits your exposure to silent billing routing bugs
- Monitor your usage dashboard closely - the error message (“out of extra usage”) gives no indication that the cause is billing routing, not actual usage
- Keep records - the affected user found the bug through systematic binary search across their git history, which is the only way this class of bug becomes discoverable
For the broader developer community, this incident is a reminder that when a company’s support system is itself an AI with no meaningful escalation path, the blast radius of any billing bug extends far beyond the technical issue itself.
