When several transactions lock the same row (foreign-key checks, SELECT … FOR SHARE), the row’s xmax cannot hold them all, so Postgres allocates a multixact id pointing to a member list stored out of line. Multixacts have their own 32-bit counter, their own age, their own freeze settings, and a second, less visible limit: the member space, about 4B entries with no built-in metric. Under heavy contention member lists grow quadratically, and member exhaustion stops writes while every age metric still looks healthy.