A developer says a stolen API key for Google Google Gemini turned a normal $180 monthly bill into $82,314 in just 48 hours.
The three-person team in Mexico discovered the breach between February 11 and 12 and quickly revoked the compromised key, disabled Gemini APIs, rotated credentials, enabled two-factor authentication, and secured their system.
Most of the charges reportedly came from Gemini 3 Pro Image and Gemini 3 Pro Text, with usage jumping 455× above normal levels.
Google Cloud cited its shared responsibility model, meaning customers are responsible for protecting their own API keys, so the charges could still apply.
If enforced, the developer says the bill could bankrupt their small company. They’ve filed a cybercrime report and are working with Google support while questioning why safeguards like spending limits or anomaly alerts didn’t trigger when usage suddenly exploded.
The case highlights a growing reality in the AI era: API keys are essentially financial keys, and ...
Suggested Credits
Tags, Events, and Projects