BotBeat
...
← Back

> ▌

Google / AlphabetGoogle / Alphabet
INDUSTRY REPORTGoogle / Alphabet2026-04-16

Developer Faces €54,000 Gemini API Bill After Firebase Browser Key Exposed to Unauthorized Requests

Key Takeaways

  • ▸Unrestricted Firebase browser keys can expose Gemini APIs to unauthorized access, resulting in severe billing consequences within hours
  • ▸Google Cloud's billing alerts and anomaly detection provide insufficient real-time protection, with delays allowing costs to spiral before remediation
  • ▸Google Cloud support declined to adjust charges even when usage was clearly anomalous and non-user-driven, raising questions about billing dispute resolution for security incidents
Source:
Hacker Newshttps://discuss.ai.google.dev/t/unexpected-54k-billing-spike-in-13-hours-firebase-browser-key-without-api-restrictions-used-for-gemini-requests/140262↗

Summary

A developer reported an unexpected €54,000+ billing spike within 13 hours of enabling Firebase AI Logic on their Firebase project, traced to unauthorized Gemini API requests originating from an unrestricted Firebase browser key. The anomalous traffic appeared automated and was not correlated with legitimate user activity, yet Google Cloud support classified the charges as valid usage and denied a billing adjustment request. The incident highlights a critical security gap where Firebase browser keys lack built-in API restrictions by default, leaving developers vulnerable to unauthorized API consumption if credentials are exposed. Despite triggering budget and cost anomaly alerts, the delayed reporting meant the developer had already incurred €28,000 in charges before taking action to disable the API and rotate credentials.

  • Current safeguards (App Check, quotas, server-side calls) may be insufficient without stricter default API key restrictions and real-time rate limiting

Editorial Opinion

This incident exposes a serious design vulnerability in Google's Firebase and Gemini API integration. While Firebase AI Logic lowers the barrier to entry for developers integrating AI features, the default lack of API key restrictions on browser-exposed credentials creates an unacceptable security risk. The fact that Google Cloud denied a billing adjustment despite clearly anomalous usage patterns suggests the company should reconsider its billing dispute policies for security-related incidents—developers should not bear the full financial burden of infrastructure vulnerabilities they didn't create.

Large Language Models (LLMs)CybersecurityRegulation & PolicyPrivacy & Data

More from Google / Alphabet

Google / AlphabetGoogle / Alphabet
UPDATE

Google Prepares Rollout of Skills Feature Across Gemini and AI Studio

2026-04-16
Google / AlphabetGoogle / Alphabet
PARTNERSHIP

Google and Pentagon in Advanced Discussions Over Classified AI Deal

2026-04-16
Google / AlphabetGoogle / Alphabet
UPDATE

Google Gemini Now Generates Personalized AI Images Using Your Google Photos Library

2026-04-16

Comments

Suggested

OpenAIOpenAI
RESEARCH

OpenAI's GPT-5.4 Pro Solves Longstanding Erdős Math Problem, Reveals Novel Mathematical Connections

2026-04-17
AnthropicAnthropic
PARTNERSHIP

White House Pushes US Agencies to Adopt Anthropic's AI Technology

2026-04-17
AnthropicAnthropic
RESEARCH

AI Safety Convergence: Three Major Players Deploy Agent Governance Systems Within Weeks

2026-04-17
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us