Stolen Gemini API Key Turns $180 Bill into $82,000
Description
A dark-mode X screenshot chain. Top post by 'Senior PowerPoint Engineer' (@ryxcommar): 'Google suggests you expose API keys client side for things like Google Maps. Google changed the permission boundaries for this overnight to push AI aggressively, so that the API keys can access Gemini as long as Gemini is enabled for the associated GCP project.' Quoted post by CG (@cgtwts): 'They went from a $180 bill to losing $81,820 in 48 hours.' Embedded is a Reddit r/googlecloud post by u/RatonVaquero (Top 1% Poster): '$82,000 in 48 Hours from stolen Gemini API Key. My monthly Usage Is $180. Facing Bankruptcy' - 'Between Feb 11 and 12, our Google Cloud API Key was comprommised (We don't know how, we didn't find an obvious mistake) and generated generated $82,314.44 in charges.' Highlights the cloud-billing blast radius when Maps-style client-exposed keys silently gain Gemini access with no hard spend caps
Comments
20Comment deleted
Google finally solved Gemini adoption metrics: enable it on every leaked Maps key and let the attackers drive usage growth
Google Maps found the fastest route from a public API key to bankruptcy.
Didn't they fix this shortly after it happened the first time? Maybe this is the screenshot of the first time Comment deleted
Source https://www.reddit.com/r/googlecloud/comments/1reqtvi/_/ Comment deleted
This is a more juicy story, https://www.reddit.com/r/googlecloud/comments/1rv3xr9/_/ Comment deleted
Not setting a spending cap on such services isnt very clever thinking Comment deleted
If your "cloud" does not allow you to set a cap then you should not use it Comment deleted
Fun fact, you can charge anyone money by accessing their S3 buckets, even without permission. Failed attempts to access a bucket still get billed. Comment deleted
that's why we set up gateways Comment deleted
6 years of professional web scrapping changed me forever. Comment deleted
is that a real thing? like what was your daily tasks? im curious Comment deleted
1. take data 2. ??? 3. profit Comment deleted
if big companies can sell my data for profit, why can't I sell their data for profit? Comment deleted
yes. customers have been paying us to get their data on our site and that it stays in sync. 95% of the time it's basically: run html through some heuristic xml repairer or dom builder, because for some reason 99.999% of web pages are syntactically invalid. then extract urls to be followed, put them into some kind of set and extract data. take next url out of the urls set, look for urls, look for data. since we've been tasked by the page owner to scrap them, most of the time we were in some kind of whitelist and didn't had to hide our doing. but there were a lot of customers, who had no IT department and tricky websites. there is where the challenge comes. it isn't hard, it's just about to have this experience and to know how to bypass securities or incompatibilities. there are lots of techniques I won't explain them in a telegram message Comment deleted
sometimes we could figure out some sqlinjection to get all the data we needed in 1 request, sometimes you need to set specific headers, sometimes you need to open pages in specific order for no explainable reason. it can get infinitely complex. 1 customer from capetown had all 3000+ pages written by hand. there was no common structure at all. Comment deleted
holy shit, im doing some projects for uni but is very hard, trying to get some data from italian government right now with scrape-parsing Comment deleted
just ask them Comment deleted
Galaxychad from-scratch reimplementer Comment deleted
cant one set a limit on costs per month for gemini? Comment deleted
We got hit 15k bill because of this shit Bye bye gcp Comment deleted