logo

Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds

ID: 09f0c209-638d-5832-8cc1-6deb00732087

STIX ID: report--09f0c209-638d-5832-8cc1-6deb00732087

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: Deeba Ahmed

...
...

Aikido Security found that deleted Google Cloud API keys continue to authenticate for an average of 16 minutes (maximum ~23) because of eventual consistency in Google’s global auth infrastructure, allowing an adversary holding a leaked key to access enabled APIs (e.g., Gemini, BigQuery, Maps) and exfiltrate data; Google declined to remediate and researchers advise treating deletion as a 30-minute process and monitoring authentications during that window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.