Retries Are a Denial-of-Wallet Attack Waiting to Happen
The invoice arrived on a Tuesday. Forty-seven thousand dollars for Lambda invocations across a weekend nobody was working. The team lead stared at CloudWatch metrics — normal traffic Friday afternoon, then a cliff of timeouts starting around 21:00. What followed wasn't an attack. No credential leak, no bot swarm. Just the application eating itself alive through retries, each failed request spawning three more, those spawning nine, the exponential curve steepening until AWS started provisioning containers faster than anyone could hit the "stop" button. This is what we mean by Denial-of-Wallet. Not malicious. Self-inflicted.
Continue reading on DZone
Opens in a new tab



