rising4월 16일· 2 sources

Unrestricted Firebase Browser Key Triggers €54K Gemini API Bill Overnight

노출된 Firebase 브라우저 키로 Gemini API 요금 €54,000 폭탄... 구글 환불 거부

Why it matters

A misconfigured Firebase project with exposed browser-accessible API keys led to rapid exploitation of Gemini APIs, accumulating €54,000+ in charges within hours. This incident exposes a critical gap in Firebase's security defaults and highlights how AI service integrations can create unexpected cost amplification vectors that cloud providers may refuse to cover, underscoring the need for stricter API validation and billing safeguards.

2
Sources
+0
24h
Growth
158d
Active
api abuseapi key exposureapi key securitybilling protectioncost controlcost escalationfirebasefirebase ai logicgemini api

Sources

Related Issues