Themata.AI
Themata.AI

Popular tags:

#developer-tools#ai-agents#llms#claude#code-generation#ai-ethics#ai-safety#openai#anthropic#open-source

AI is changing the world. Don't stay behind. Clear summaries, community insight, delivered without the noise. Subscribe to never miss a beat.

© 2026 Themata.AI • All Rights Reserved

Privacy

|

Cookies

|

Contact
cloud-computingapi-managementbilling-issuesai-safety

Google Cloud customer wakes up to $18,000 bill despite $7 budget

Google Cloud customer wakes up to $18,000+ bill despite $7 budget, thanks to forgotten API key in published project — attacker put in 60,000+ requests and blasted through $1,400 spending cap

tomshardware.com

April 22, 2026

6 min read

🔥🔥🔥🔥🔥

47/100

Summary

A Google Cloud customer received an $18,000 bill after an attacker exploited a forgotten API key, making over 60,000 requests and exceeding a $1,400 spending cap. Safety measures for API keys are turned off by default, leading to the unexpected charges.

Key Takeaways

  • A Google Cloud customer received an unexpected bill of over $18,000 due to an attacker exploiting a forgotten API key, resulting in over 60,000 requests.
  • Google Cloud's safety features, which could have prevented the incident, were turned off by default.
  • The customer's account was automatically upgraded to a higher spending tier without notification, significantly increasing the billing cap during the attack.
  • Cybersecurity experts have raised concerns about the risks associated with Google Cloud's single API key format, especially with the activation of the Gemini API.
Read original article

Community Sentiment

Negative

Positives

  • Switching to providers like Hezner, which offer hard billing limits, can protect consumers from unexpected charges, making cloud services more accessible and manageable.

Concerns

  • The lack of a feature to automatically shut down services at a billing cap exposes customers to significant financial risks, highlighting a major flaw in GCP's billing practices.
  • Google's billing practices are perceived as predatory, with users feeling that the company profits from unexpected charges without accountability.
  • The current cloud billing paradigm, which allows for indefinite charges, is criticized as being unsustainable and unfair for normal consumers and small businesses.

Related Articles

Google API Keys Weren't Secrets. But then Gemini Changed the Rules. â Truffle Security Co.

Google API keys weren't secrets, but then Gemini changed the rules

Feb 25, 2026

Unexpected €54k billing spike in 13 hours: Firebase browser key without API restrictions used for Gemini requests

€54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

Apr 16, 2026

LLMHorrors | Stolen Gemini API key racks up $82,000 in 48 hours

Stolen Gemini API key racks up $82,000 in 48 hours

Mar 3, 2026

Account Restricted Without WARNING– Google AI Ultra / OAuth via OpenClaw

Google restricting Google AI Pro/Ultra subscribers for using OpenClaw

Feb 22, 2026

Addressing Antigravity Bans & Reinstating Access · google-gemini/gemini-cli · Discussion #20632

Addressing Antigravity Bans and Reinstating Access

Feb 28, 2026