• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - AI Trends and Related News - Google Cloud User’s $7 Budget Skyrockets to $18,000 Upon Waking — Exposed APIs in Public Projects Being Abused

Google Cloud User’s $7 Budget Skyrockets to $18,000 Upon Waking — Exposed APIs in Public Projects Being Abused

Rocky by Rocky
April 23, 2026 - Updated on August 5, 2026
in AI Trends and Related News

We had just reported that there was…Developer Shares Horror Story of Stolen Gemini API Key Resulting in Over NT$2.6 Million in Charges Within 48 Hours, but recently a similar situation played out again. This time, the victim is an Australian person AI The consultant had originally set a budget limit of only about 10 AUD (approximately 210 TWD) in his account, but when he woke up, he found the bill had skyrocketed to 25,672 AUD (approximately 580,000 TWD), shocking him entirely. More importantly, this time the attacker didn’t steal his API a key, but rather through what he had used a few months ago Google AI Studio For testing, use the URL of the project deployed as a public Cloud Run service. Any request sent to this URL will automatically trigger the service to use the API key stored within it to call Gemini.

Google Cloud users wake up to a massive bill of NT$580,000! Budget set at just $7, publicly exposed Cloud Run service attacked by hackers with 60,000 requests slammed through

According to Tom’s HardwareJesse Davies, founder of an AI startup, shared the incident on LinkedIn and on the r/googlecloud subreddit on Reddit, hoping others would learn from it.

Davies said he recently did a small project test using Google AI Studio, and deployed it to the cloud with one click using the “Deploy to Cloud Run” feature, after which he didn’t touch it again. He was quite familiar with Google AI Studio and had taken some security measures, such as using different API keys for each project, separate billing accounts, two-factor authentication, and Cloud Audit Logs, among others. Unexpectedly, something still went wrong in the end.

Went to bed with a $10 budget alert. Woke up to $25,672.86 in debt to Google Cloud.
byu/venturaxi ingooglecloud

His Google Cloud account budget alert was set to 10 AUD (approximately $7 USD). One morning, he woke up to find that his credit card had already been charged 10,000 AUD. He quickly contacted Google support, but while waiting for a response, an additional 15,000 AUD was charged to his account, bringing the total to 25,672.86 AUD (approximately $18,391 USD)—an increase of over 2,500 times the original 10 AUD budget he had set.

More critically, Davies emphasized that the attackers never actually stole his API keys. They simply found the publicly exposed URL where the service was deployed on Cloud Run and started sending requests directly to it. Google’s own proxy service would then use the API keys stored in plaintext within the container, signing each request for the attackers one by one and sending them to Vertex AI to execute. In just one night, the attackers sent over 60,000 requests.

Additionally, his account was originally at Tier 2, which has a spending limit of around $2,000. When spending exceeds $1,000, the account is automatically upgraded to a higher tier, with the new limit jumping to between $20,000 and $100,000 — a process Google does not notify users about.

In his follow-up compilation, Davies found that Google Cloud has 9 built-in security mechanisms to block this type of attack, but they are all disabled by default and require manual activation one by one through the settings page.

In the end it turned out pretty well — Google agreed to waive the charge, and the amount already deducted by the bank was refunded. Davies himself also scheduled a meeting with Google’s management for further review.

In fact, it’s not just Davies who experienced this—many netizens also came forward in the post to share their own cases.

As user juanpare mentioned, Google’s Cost Anomaly Detection system did catch a $975 abnormal charge on his Gemini API and proactively sent an alert email. But he was asleep at the time, and by the time he saw the email at 6 AM the next morning and immediately deleted the two leaked keys, the bill had already skyrocketed from $975 to $18,596 (approximately NT$580,000) — a 19-fold increase in just 7 hours.

Google Cloud detected $975 of API key fraud on my account, sent one email at 11 PM, then let the bill grow to $18,596 — 5 support agents have refused to help (case 70257996)
byu/juanpare ingooglecloud

So when using APIs, you really need to be careful, especially with Google Cloud. If you have services like Cloud Run, App Engine, or Cloud Functions that you no longer use, remember to go to the dashboard and completely delete them, don’t just disable them. A lot of times, as long as the URL still exists or the API is still running, there’s a risk of it being found and abused.

Next, also avoid placing API keys in plaintext within container environment variables. Instead, use Google Secret Manager or short-lived credentials (OAuth 2.0, service account short-lived tokens) to replace long-lived keys.

Source: KOCPC Chinese

Tags: ApiGeminiGoogleGoogle AI StudioReddit

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology