BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Google API Keys Expose Gemini, Data, Bills

Exposed Google Cloud API keys unlock Gemini AI access, risking data and massive bills.

  • Google Cloud API keys embedded in public website code can be abused to authenticate to Gemini AI endpoints.
  • Researchers found nearly 3,000 exposed keys and warn of risks like quota theft and access to private data.
  • A recent Reddit post detailed an instance of $82,000 in charges from a potentially stolen key.
  • Google states it has implemented measures to detect and block leaked keys attempting to access the Gemini API.

Security researchers at Truffle Security revealed in recent research that publicly accessible Google Cloud API keys can be weaponized to access sensitive Gemini AI endpoints. This critical vulnerability emerged after users enabled the Generative Language API, retroactively granting old billing keys new AI privileges. Consequently, these keys, designed for services like maps, became live credentials for AI models without warning.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The company discovered 2,863 such keys live on the public internet, according to their report. With a valid key, an attacker can access uploaded files and cached data while charging LLM usage to the victim’s account. Researcher Joe Leon emphasized that keys “now also authenticate to Gemini even though they were never intended for it.”

Meanwhile, a similar investigation by mobile security firm Quokka found over 35,000 unique Google API keys in Android apps. They warned that this “creates a risk profile that is materially different,” as detailed in their own analysis. The issue potentially allows for automated LLM requests and quota consumption, leading to massive bills.

Google has since addressed the problem, with a spokesperson confirming proactive measures are in place. However, the real-world impact may already be significant, as suggested by a user reporting exorbitant charges. Security strategist Tim Erlin noted this demonstrates how “risk is dynamic, and how APIs can be over-permissioned after the fact.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Afroman Token Soars After He Wins Defamation Trial

The $FRO token spiked over 4,600% to a $335,000 market cap in the two...

Trader Warns Bitcoin Could Drop Below $60,000

Professional trader Alessio Rastani warns Bitcoin could fall below $60,000 before a meaningful bottom...

Nvidia to sell 1 million GPUs to Amazon by 2027

NVIDIA will supply one million GPUs to Amazon Web Services between 2027, according to...

Altcoin Trading Volume Plunges 80% on Binance: Report

Altcoin trading volume on Binance has plunged 80-85% from roughly $40 billion to $7.7...

Bitcoin Price Nears Key RSI Bull Divergence Level

Bitcoin's weekly relative strength index is nearing a crucial position that could signal the...

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading