I have reproduced this easily. When using a new signing key the system will download and try to update the firmware in an endless loop but never succeed. This can easily generate GB of data usage per device in a single day.
My initial failure wasn’t using a different key so there are definitely other failure methods that will generate this excessive data.
Any IOT system needs to be robust enough to not allow these kinds of data intensive loops and this is the third one I’ve come across. The other two are: