Exposed Google API keys grant attackers free access to Gemini AI, costing developers thousands
A critical security flaw in Google's API key architecture is allowing attackers to exploit Gemini AI without authorization, causing developers severe financial damage. CloudSEK discovered 32 exposed Google API keys across 22 Android apps with over 500 million combined installs, including OYO Hotel Booking App and Google Pay for Business. One solo developer faced a $15,400 bill, while a Japanese company saw $128,000 in unauthorized charges.