Stolen Gemini Key Ran Up an $82,314 Google Cloud Bill in 2 Days
- Platform
- Google Cloud
- When
- February 2026
- Bill
- $82,314
- Outcome
- Not waived as of the last public update in March 2026; Google cited shared responsibility
In February 2026, a three-person startup in Mexico found $82,314.44 in Google Cloud charges after someone used its API key to call Gemini models for about two days. The team normally spent about $180 a month. A developer on the team described the bill on Reddit, and The Register covered it in early March.
What happened
- February 11 to 12, 2026: According to the developer, the company's Google Cloud API key was compromised and used to generate $82,314.44 in charges. Almost all of it was for Gemini 3 Pro Image and Gemini 3 Pro text. That is roughly 455 times the team's normal monthly spend.
- Response: The team deleted the key, disabled the Gemini APIs, rotated credentials, turned on two-factor authentication, tightened IAM permissions and opened a Google support case.
- February 25, 2026: The developer posted in r/googlecloud. They said their account manager had pointed to Google Cloud's shared responsibility model and that the company would be charged. They also said that paying even a third of the bill would bankrupt the company.
- March 3, 2026: The Register reported the case. Google would not say whether the developer must pay.
How the key leaked is not known. The developer said they found no obvious mistake. In later replies they said the key was never committed to GitHub, correcting readers who took an earlier reply to mean it had been. They also said they could not tell where the requests came from.
The Register put the case next to research that Truffle Security published on February 25, 2026. Google API keys that start with AIza were long treated as public identifiers. Truffle found that turning on the Gemini API in a project gives existing keys in that project access to Gemini. Scanning a November 2025 web crawl, it found 2,863 live keys exposed this way. Nothing public links this startup's key to that issue, but it shows how a key that was never meant to be secret can start running up Gemini charges.
Why the bill got so big
Gemini is billed per token, and image generation is expensive per call. Google's current Vertex AI pricing lists Gemini 3 Pro Image at $120 per million image output tokens. A 1K or 2K image uses 1,120 tokens, or about $0.134. A 4K image uses 2,000 tokens, or about $0.24. Text output costs $12 per million tokens.
The developer did not share the split between images and text, so this is only an illustration. If the whole bill had been 1K or 2K images, it would come to about 614,000 images, or about 3.6 images a second for 48 hours. If it had all been text output at $12 per million tokens, it would be about 6.9 billion tokens.
The developer said they had basic alerts, but nothing stopped usage, and there was no default per-API spending cap. Charges also kept appearing after the key was disabled, because billing data lags behind usage.
How it ended
As of the last public update, the bill had not been waived. On February 27 the developer wrote that Google kept telling them there was no path except paying. On March 19, 2026, they wrote that they were still liable and hoped to work something out with Google. We found no later public update from the developer or Google as of October 2026.
Google did change Gemini billing afterward. On March 16, 2026, it announced project spend caps and billing-account tier caps for the Gemini API. These did not exist when this key was abused.
How to protect your Google API keys
- Restrict every key. Google's API key docs say plainly, "Unrestricted API keys are insecure." Add an API restriction so the key can call only the APIs it needs. Also add an application restriction: HTTP referrers, IP addresses, or Android or iOS apps. See Manage API keys. The Gemini API now rejects unrestricted standard keys, and new keys made in AI Studio are bound to a service account and limited to Gemini by default. See Using Gemini API keys.
- Audit old keys before you turn on Gemini. Truffle Security suggests checking each project for the Generative Language API. If it is on, review every key under Credentials, starting with the oldest, and rotate any that appear in client-side JavaScript or a public repo.
- Keep keys out of client code and repositories. Google's API key best practices say to have your server attach the key. The Gemini docs say never to expose keys client-side in production and to call the API through a backend proxy.
- Set a Gemini spend cap. In AI Studio you can set a monthly project spend cap. It is marked experimental and can lag by about 10 minutes, and you pay for overages in that window. Billing accounts also have tier caps: $250 at Tier 1, $2,000 at Tier 2 and $20,000 to $100,000 at Tier 3. When the account hits its cap, all linked projects pause until the next month. See Gemini API billing.
- Lower quotas on other paid APIs. On an API's Quotas tab you can cap requests per day or per minute. Quotas limit request volume, not dollars, and enforcement lags, so leave a buffer. See Capping API usage.
- Treat budget alerts as alerts only. An alerts-only budget does not cap spending. Usage costs reach Cloud Billing after a delay, and the first notification can take several hours after you create a budget. To act automatically, connect a Pub/Sub topic and disable billing from code. See Create, edit, or delete budgets and budget alerts.
- Rotate and delete. Rotate keys on a schedule and delete ones you no longer use. If a key may have leaked, create its replacement, update your app, then disable the old key. Deleted keys can be restored within 30 days.
What would have caught it sooner
This team went from about $6 a day to tens of thousands of dollars a day, and the basic alerts they had did not stop it. A check that compares recent usage to the normal level would flag a jump that size early, though someone still has to act on the alert. CostHex reads usage every minute and sends an alert to Slack, Discord, Telegram or email with a link to the resource. It is read-only by default. Today it supports Cloudflare Workers only. Google Cloud support is next, and per-key leak detection for OpenAI, Anthropic and Gemini comes after that. None of that is available yet, so it would not have helped here.
Sources
- Developer's Reddit post: "$82,000 in 48 Hours from stolen Gemini API Key" (with follow-up replies), Reddit, r/googlecloud
- Dev stunned by $82K Gemini API key bill after theft, The Register
- Google API Keys Weren't Secrets. But then Gemini Changed the Rules., Truffle Security
- Vertex AI generative AI pricing (Gemini 3 Pro Image), Google Cloud
- Giving you more transparency and control over your Gemini API costs, Google
- Gemini API billing: spend caps, Google AI for Developers
- Using Gemini API keys, Google AI for Developers
- Manage API keys, Google Cloud
- Best practices for managing API keys, Google Cloud
- Capping API usage, Google Cloud
- Create, edit, or delete budgets and budget alerts, Google Cloud