‘Silent’ Google API key change exposed Gemini AI data
‘Silent’ Google API key change exposed Gemini AI data
Google Cloud Platform API keys, historically used only for billing identification (prefixed 'Aiza'), silently became authentication credentials for the Gemini AI API from late 2023 onward without notifying developers. Researchers at Truffle Security found 2,863 live exposed keys via a Common Crawl scan, affecting major financial institutions, security firms, and even Google itself.
Attackers could extract these public keys from site source code to access private Gemini data—uploaded files, cached content, datasets—or rack up large API bills. Google initially dismissed the report as intended behavior but later acknowledged the bug and restricted the exposed keys from Gemini access.
Mitigation steps include auditing GCP console for unrestricted or Generative Language API-enabled keys and rotating any that are public. Google's roadmap now includes defaulting new AI Studio keys to Gemini-only access and blocking detected leaked keys.
Tags
[#security](/content/tags/security "Check all #security posts"/index.html) [#gcp](/content/tags/gcp "Check all #gcp posts"/index.html) [#google-gemini](/content/tags/google-gemini "Check all #google-gemini posts"/index.html)
Feb 27•4m read time•From infoworld.com