Dev stunned by $82K Gemini bill after unknown API key thief goes to town
ID: 5b0e8c3a-ff4a-5a6e-9d1b-96527514881a
STIX ID: report--5b0e8c3a-ff4a-5a6e-9d1b-96527514881a
Feed Name: The Register (Security)
A developer's Google Cloud API key was compromised and abused to incur $82,314.44 in Gemini 3 Pro charges within 48 hours; Truffle Security found 2,863 live Google API keys publicly exposed that can authenticate to Gemini, enabling attackers to access uploaded/cached data and bill LLM usage to victims. Google reclassified the issue from "intended behavior" to a bug after Truffle's disclosure and is working on mitigations, while Truffle recommends scanning repositories and assets with TruffleHog to find leaked keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
