5 Sources
[1]
Gemini API key thief racks up $82,314 in charges in just two days, victim 'facing bankruptcy' -- affected devs call for basic guardrails against 'catastrophic usage anomalies'
A Google Gemini user has taken to Reddit "in a state of shock and panic." The issue is with the most recent bill received by their software development business. Redditor RatonVaquero's typical monthly spend on Gemini AI services is $180. However, in just 48 hours last month, their account
[2]
Dev stunned by $82K Gemini API key bill after theft
Probably not an isolated incident only as researchers have already found 2,863 live API keys exposed A developer says their company is on the hook for more than $82,000 in unauthorized charges after a stolen Google Gemini API key racked massive usage costs up in just 48 hours. "I am in a state of
[3]
Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement
New research has found that Google Cloud API keys, typically designated as project identifiers for billing purposes, could be abused to authenticate to sensitive Gemini endpoints and access private data. The findings come from Truffle Security, which discovered nearly 3,000 Google API keys
[4]
A stolen Gemini API key turned a $180 bill into $82,000 in two days
Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. AI Economy: A team of three developers in Mexico is facing a roughly 455× increase in monthly AI service expenses after an API key associated with their project was allegedly compromised. The key
[5]
Generative AI Rollout Exposes Hidden Risk in Google Cloud API Keys
Generative AI Rollout Transforms Harmless Google API Keys Into Critical Cloud Security Vulnerability A quiet change in how Google's cloud services interact has opened an unexpected security gap, putting thousands of organisations at risk of data exposure and mounting AI bills. Security researchers
Share
Copy Link
A Mexican development firm faces bankruptcy after thieves exploited a compromised Gemini API key, racking up $82,314 in charges within two days—a 455× spike from their usual $180 monthly bill. Security researchers discovered nearly 3,000 exposed Google Cloud API keys that inadvertently gained Gemini access, transforming once-harmless project identifiers into critical security vulnerabilities.
A three-person development team in Mexico is confronting financial ruin after a stolen Gemini API key generated $82,314.44 in unauthorized charges between February 11 and February 12, 2026
1
. The company, which typically spends $180 per month on Google Cloud services, experienced a 455× usage spike in just 48 hours4
. Developer RatonVaquero shared their predicament on Reddit, stating the firm faces bankruptcy if Google enforces even a third of these charges. The unauthorized API usage primarily involved Gemini 3 Pro Image and Gemini 3 Pro Text services, with thieves exploiting the compromised credentials to generate massive volumes of AI content on the victim's account2
.
Source: The Register
Google representatives have cited the company's Shared Responsibility Model when addressing the $82,000 in charges, indicating the developer may remain liable for the unauthorized API usage
1
. Under this framework, Google Cloud secures its platform while users must implement authentication systems, access policies, and network security to protect their credentials2
. The affected developers have since deleted the compromised key, disabled Gemini APIs, rotated credentials, enabled two-factor authentication, locked down IAM, and filed a cybercrime report with the FBI1
. Despite these remediation efforts, initial support interactions suggest Google may not offer payment adjustments, leaving the small business in financial jeopardy.Truffle Security researchers uncovered a systemic API key vulnerability affecting thousands of organizations. Their investigation revealed 2,863 live public Google API keys with inadvertent Gemini access
2
. The security flaw stems from how Google Cloud API keys, originally designed as project identifiers for billing purposes, now authenticate to Gemini endpoints after the generative AI service is enabled3
. These keys, identifiable by the "AIza" prefix, were embedded in client-side code for services like Google Maps and Firebase based on Google's earlier guidance that API keys were not secrets3
. Truffle Security researcher Joe Leon explained that attackers with valid keys can access uploaded files, cached data via /files and /cachedContents API endpoints, and charge LLM usage to victim accounts3
.
Source: Hacker News
The vulnerability highlights how legacy credentials gain sensitive privileges without developer awareness. When users enable the Gemini API on a Google Cloud project through the Generative Language API, existing API keys in that project automatically gain access to Gemini endpoints without warning. Additionally, creating new API keys in Google Cloud defaults to "Unrestricted" status, making them applicable for every enabled API in the project, including Gemini
3
. Quokka's separate research scanning 250,000 Android apps found over 35,000 unique Google API keys embedded in mobile applications3
. This transformation of harmless billing tokens into live authentication credentials represents what security experts call a dynamic risk scenario where generative AI security concerns intersect with cloud infrastructure vulnerabilities5
.Related Stories
Affected developers are calling for basic spending guardrails against catastrophic usage anomalies, arguing that cloud providers should implement automatic safeguards when billing patterns deviate dramatically from established norms
1
. The Mexican development team noted that personal Gemini customers have usage caps preventing overspending, while business users can set quotas limiting requests per day or minute, and Google Cloud Vertex AI users can configure budget alerts1
. However, these protections require proactive configuration and don't include mandatory spending caps that would prevent unauthorized API usage from generating ruinous bills. The developers argue that features like temporary service freezing pending review and mandatory verification for extreme billing spikes should be standard protections.Source: TechSpot
After Truffle Security presented their findings through Google's Vulnerability Disclosure Project, the company initially classified the report as "intended behavior" before upgrading it to "Bug" status in December 2025 when researchers provided examples from Google's own infrastructure
2
. A Google spokesperson stated the company has "implemented proactive measures to detect and block leaked API keys that attempt to access the Gemini API"3
. However, as of February 2026, Truffle Security reported not seeing a concrete outcome from the root-cause fix Google was developing2
. Organizations using Google Cloud should verify if AI-related APIs are enabled in their projects and rotate keys that may be publicly accessible, prioritizing oldest keys first since they were most likely deployed under previous guidance treating API keys as safe to share3
. Truffle Security offers TruffleHog, an open-source secrets scanning tool, to help identify exposed credentials across code repositories and web assets2
.Summarized by
Navi
[2]
[3]
[5]
09 Apr 2026•Technology

24 Feb 2026•Technology

14 Jul 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology