Google API keys exposed in 22 apps allow attackers to freely access Gemini AI, resulting in losses of hundreds of thousands of people.


  • Exposed Google API keys allow attackers to execute unlimited Gemini AI requests
  • Developers experience serious financial losses due to unauthorized access to AI infrastructure
  • Encrypted credentials convert public identifiers into active authentication tokens for Gemini AI

Developers face serious consequences as exposed Google API keys are exploited to access Gemini AI without authorization, resulting in significant financial losses, experts warned.

CloudSek security researchers discovered that the root cause of these incidents lies in the inadvertent elevation of publicly available API keys to active Gemini AI credentials.



scroll to top