Deleted Google API keys keep working for up to 23 minutes, researchers warn
ID: f6274638-2b1c-5235-8eba-c242654514d8
STIX ID: report--f6274638-2b1c-5235-8eba-c242654514d8
Feed Name: Help Net Security
Aikido Security found that deleted Google API keys can still authenticate for a median of ~16 minutes (up to 23 minutes) due to eventual consistency in Google Cloud, meaning key deletion is not immediately effective; this affects keys for Gemini and other GCP APIs. Researchers note misleading UI messaging and lack of a way to confirm revocation; faster revocation is possible for other key types, but Google currently treats the delay as expected, so users should monitor API usage and assume a ~30-minute window before deletion is fully effective.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
