Google Cloud Offers Partial Credit for Unauthorized Gemini API Charges After Security Flaw
A Google Cloud customer recently received a 75% discretionary credit from Google, totaling approximately $96,000, to cover unauthorized Gemini API usage that resulted in a staggering $128,000 bill. This resolution comes after the user publicly detailed their predicament, revealing that their AIza API key, originally intended for a different service, was silently granted access to the Gemini API without notification.
The root cause of these exorbitant charges is a significant security vulnerability. In January 2026, Truffle Security disclosed a "Tier 1 privilege escalation bug" to Google. This bug allowed existing AIza API keys to access the Gemini API, effectively expanding their permissions without the account holder's knowledge or consent. Attackers exploited this oversight, leading to massive unauthorized usage, particularly for cryptocurrency mining and hammering AI models.
The affected customer, who runs a small platform supporting rural artisans, faced potential bankruptcy due to the unexpected charges. Initially, Google's support reportedly stated "no fraud found" and "no account compromise detected," despite the clear unauthorized activity. The recent offer of a partial credit, updated today, signifies a shift in Google's response to the issue, acknowledging the impact of the unannounced API key scope expansion. This incident underscores the critical importance of transparent API permission management and robust security notifications for cloud users.
Read original source