Google Gemini stolen API key sends bill skyrocketing

A team of three developers in Mexico are facing a bill that is 450 times higher than their monthly AI service fees after they claim an API key they were using on a project was compromised.

The key was later used to access Google Gemini services on a large scale. The small company reportedly tried to negotiate with Google, but the company did not offer any payment adjustments.

See more articles from iGuRu.gr when you search for news on Google.

One of the affected developers shared the incident on Reddit . According to the post, the Google Cloud API key was compromised between February 11 and 12 and was primarily used to access the Gemini 3 Pro Image and Gemini 3 Pro Text services.

The company’s typical monthly fee for AI services was about $180, but the unauthorized use resulted in a bill of about $82.314,44. The developers say they were operating under tight financial conditions and hoped their product would eventually become profitable. Even if only a third of the amount charged is collected, they fear the cost could drive their business into bankruptcy.

A Mountain View spokesperson said that customers using AI services are responsible for the security of their credentials under the platform’s Shared Responsibility Model . Under that framework, users are expected to implement appropriate safeguards, as service providers may not be held liable for misuse resulting from compromised authentication keys.

The developers said they don’t believe they made any “obvious” operational errors. After discovering the compromised key, they attempted to secure their system by deleting the exposed keys, disabling access to the Google Gemini API, and enabling two-factor authentication on all their accounts. They also opened a support ticket with Google, though they say they haven’t received any meaningful resolution so far.

One of the developers argued on Reddit that cloud providers should implement stronger safeguards against extreme charging scenarios. The developer suggested that platforms should stop or automatically verify charges once usage reaches abnormal limits, citing the lack of mandatory confirmation mechanisms during sudden usage spikes.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).