Google API keys exposed in 22 apps allow attackers to freely access Gemini AI, causing hundreds of thousands of losses.


  • Exposed Google API keys allow attackers to execute unlimited Gemini AI queries
  • Developers suffer serious financial losses due to unauthorized access to AI infrastructure
  • Hardcoded credentials elevate public IDs to active auth tokens for Gemini AI

Developers face serious consequences as exposed Google API keys are exploited to access Gemini AI without authorization, leading to significant financial losses, experts have warned.

CloudSek security researchers discovered that the root cause of these incidents lies in the unintentional elevation of publicly available API keys to live Gemini AI credentials.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top