
tomshardware.com
April 22, 2026
6 min read
47/100
Summary
A Google Cloud customer received an $18,000 bill after an attacker exploited a forgotten API key, making over 60,000 requests and exceeding a $1,400 spending cap. Safety measures for API keys are turned off by default, leading to the unexpected charges.
Key Takeaways
Community Sentiment
Positives
Concerns

Google API keys weren't secrets, but then Gemini changed the rules
Feb 25, 2026

€54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
Apr 16, 2026

Stolen Gemini API key racks up $82,000 in 48 hours
Mar 3, 2026

Google restricting Google AI Pro/Ultra subscribers for using OpenClaw
Feb 22, 2026

Addressing Antigravity Bans and Reinstating Access
Feb 28, 2026