Google API keys keep working after you delete them
ID: 40600417-8aa6-5254-96ce-ab6d86da09e0
STIX ID: report--40600417-8aa6-5254-96ce-ab6d86da09e0
Feed Name: Aikido Security's Blog
Researchers measured that deleted Google API keys can remain valid for minutes (median ~16, max ~23), due to eventual-consistency in revocation propagation; during that window, an attacker with a leaked key can continue calling enabled APIs (including Gemini) and exfiltrate data. The behavior is inconsistent across regions and trials, the GCP console hides deleted keys and groups their usage as apikey:UNKNOWN, and while some Google credential types revoke much faster, standard Google API keys present a long-lived revocation window that breaks user expectations and incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
