Exposed Google API keys across 22 apps give attackers free access to Gemini AI, causing hundreds of thousands in losses


  • Exposed Google API keys allow attackers to run unlimited Gemini AI requests
  • Developers experience severe financial losses due to unauthorized access to AI infrastructure
  • Hardcoded credentials elevate public identifiers to active authentication tokens for Gemini AI

Developers face serious consequences as exposed Google API keys are exploited to access Gemini AI without permission, leading to significant financial losses, experts have warned.

Security researchers from CloudSek found that the root cause of these incidents lies in the accidental elevation of publicly available API keys to live Gemini AI credentials.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top