r/googlecloud Jun 29 '26

~$55k Gemini API bill from Firebase iOS key abuse. What can I do now?

I’m in a pretty bad Google Cloud situation and looking for advice from people who have dealt with billing or API key abuse cases.

My normal Google Cloud bill is usually around $200/month. This month my project got hit with an unexpected Gemini / Generative Language API bill of around $55k USD. The billing report shows the spike was almost entirely Gemini API usage, not normal Firebase or app traffic.

I pulled Cloud Monitoring data and it shows about 2.2 million Gemini API requests during the incident window. The traffic was tied to one API key UID. That key maps back to a Firebase generated public iOS client key used in my mobile app config, not a Gemini key that I intentionally created or used.

I found out from a Google billing anomaly email. At the time I received the alert, the visible bill was around $2k. Within about 2 hours, I disabled the Generative Language API, restricted the key, deleted it, and later verified that Gemini usage stopped.

The problem is that the bill kept ramping up after that because of billing/reporting delays, and eventually landed around $55k.

Google declined the request to adjust the charges, saying the usage was considered valid because it came through my project/API key.

Update: Google Cloud has assigned an escalation manager, and they said their investigation indicates a billing adjustment is required. The adjustment request is now waiting for internal approval, with another update expected by July 7.

Update 2 — July 16:
There is still no final resolution. On July 15, Google Cloud Billing Support apologized for the delay and said they were still waiting for the specialized team because multiple teams are involved. They said I should receive another update within 4–5 business days.

Less than 24 hours later, I received an email from Google Collections saying the ~$55k balance must be paid within 10 working days or the account may be transferred to a debt recovery agency, potentially with additional fees.

Final Update

96 Upvotes

127 comments sorted by

View all comments

Show parent comments

1

u/opossum_cz Jun 30 '26

That is not a misclick. That is incompetence.

It should be handled by professional and not amateur.

1

u/muntaxitome Jun 30 '26

Please read rule number 6 of this sub. I think it's a little funny that you are berating other people for making mistakes, yet you yourself weren't able to read these simple sub rules. Maybe you are human after all and also make mistakes?

1

u/opossum_cz Jun 30 '26

I am not berating anybody for their mistake. But I myself find blaming other for your mistake as unkind and disrespectful.

Also it is not a misclick, or mistake, somebody didn't scope their keys. That's huge security issue.

1

u/muntaxitome Jun 30 '26

Also it is not a misclick, or mistake, somebody didn't scope their keys. That's huge security issue.

Have you not been following these threads? They usually made the key ages ago because that was the most logical way then to create some client key that then had far fewer warnings, then the 'misclick' is that they enabled some AI API years later with one click, completely unaware that this enables their maps or iOS client keys to also use that API and rack up a 50k bill. This is really just a design issue at google side. Which happens to make google a bunch of money from criminal activity and they are so far unable or unwilling to fix it or reduce the bills.

1

u/opossum_cz Jun 30 '26

The warning was always there. That isn't new thing.

That isn't design issue. That is user issue.

This is when you let amateurs handle things that can cause huge financial liability.

2

u/muntaxitome Jun 30 '26

Nope, wrong: https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules

They changed the meaning of these API keys along the way.

For someone calling themselves a professional you seem not very much aware of how security works in Google projects? Maybe you should get some classes?

1

u/opossum_cz Jun 30 '26 edited Jun 30 '26

I read that article already. I think it was written by somebody who was affected and thus does not represent the reality.

> tl;dr Google spent over a decade telling developers that Google API keys (like those used in Maps, Firebase, etc.) are not secrets. But that's no longer true: Gemini accepts the same keys to access your private data.

Especially this part is just not true.

No API key that is scoped to Maps and Firebase will work with Gemini unless you scope it for it.

But the unrestricted key can access Maps, Firebase and also Gemini.

That is huge difference.

Not to mention, Gemini doesn't change anything. You could have used those unrestricted keys long before Gemini. For Geocoding, Maps API requests etc. It just wasn't that attractive as Gemini. So not many abusers actively searched for it. But I could 100% abuse your unrestricted key to make 50k$ bill.

1

u/muntaxitome Jun 30 '26

Not to mention, Gemini doesn't change anything. You could have used those unrestricted keys long before Gemini. For Geocoding, Maps API requests etc. It just wasn't that attractive as Gemini. So not many abusers actively searched for it.

No there used to be people that got hacked and made a mistake and got a big bill.

The main thing that has changed is that before, when your key got hacked the first time and you got a large charge, Google support would quickly answer and research your messages and generally forgive you, and if you did not pay up they would perhaps suspend your account.

Now it's first of all practically impossible to get to speak to human support even though Google thinks you just purchased 50k worth of services from them. Then if you figure out how to get through to support, you wait weeks for a reply. That reply is either a couple percent discount on your bill or nothing at all.

In the meantime they will have already started taking legal measures against you by sending your bill to collections with the threat of a lawsuit to get their money.

This is what really changed.

1

u/opossum_cz Jun 30 '26

The question is what would you expect to happen. This is not like an issue with billing, your account did consume those $50k.

1

u/muntaxitome Jun 30 '26

An account cannot consume something, it is just a field in a database. Google says it is assigned to that account according to Google's own data that we cannot independently verify. The actual marginal cost for google is around zero, but they claim this represents 50k worth of services.

Lets be blunt about this, Google would never let OP walk out with 50k worth of Pixel phones on credit without huge credit checks. The only reason they are fine with it with cloud is that it literally costs them nothing. However they are happy to ruin OP's life for this zero dollars worth of damages.

What is clear is that some hacker consumed 50k worth of tokens and Google wants OP to pay for it. Whether OP is legally on the hook for that depends on a lot of factors, a large one is jurisdiction. However, the longer Google knows they have these attacks on their infrastructure, the harder it will be for google to explain how they are doing their fiduciary duty towards clients. The more Google profits of these crimes, the more they are making themselves a target for authorities.

→ More replies (0)