How can such overusage happen?

this is why its recommended to keep a good amount of extra capacity just incase this happens… in the future i’m sure we will be able to go closer to the theoretical max.
nodes are continually deleting and getting new ingress… 500MB is ½ a GB
so you are about 1/3600th off in relation to your capacity.

keeping stuff within such narrow limits is quite a challenge in most things.
and these numbers are also estimates i think…

every time the filewalker is run a node counts all files and their sizes and then calculates from there until next time the filewalker is run, usually on node reboots.
so over time it is bound to deviate