logo

Dev stunned by $82K Gemini bill after unknown API key thief goes to town

ID: 5b0e8c3a-ff4a-5a6e-9d1b-96527514881a

STIX ID: report--5b0e8c3a-ff4a-5a6e-9d1b-96527514881a

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A developer's Google Cloud API key was compromised and abused to incur $82,314.44 in Gemini 3 Pro charges within 48 hours; Truffle Security found 2,863 live Google API keys publicly exposed that can authenticate to Gemini, enabling attackers to access uploaded/cached data and bill LLM usage to victims. Google reclassified the issue from "intended behavior" to a bug after Truffle's disclosure and is working on mitigations, while Truffle recommends scanning repositories and assets with TruffleHog to find leaked keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.