5.3 C
United Kingdom
Saturday, April 11, 2026

Exposed Google API keys across 22 apps let attackers access Gemini AI freely, causing hundreds of thousands in losses




  • Exposed Google API keys allow attackers to run unlimited Gemini AI requests
  • Developers experience severe financial losses due to unauthorized access to AI infrastructure
  • Hardcoded credentials elevate public identifiers into active authentication tokens for Gemini AI

Developers are facing severe consequences as exposed Google API keys are exploited to access Gemini AI without authorization, leading to significant financial losses, experts have warned.

Security researchers from CloudSek found the root cause of these incidents lies in the unintended elevation of publicly available API keys into live Gemini AI credentials.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles