Incidents/ By cause/ Leaked credentials/ gemini-key-55k-gcp
BLOCK Leaked credentials Google (Gemini) student 2025

Leaked Gemini API key led to a $55,444.78 Google Cloud bill

A student was billed $55,444.78 on Google Cloud after a Gemini API key was leaked through a public GitHub repository and abused.

Reported loss$55,444.78
Which rule would have stopped this?

An API key was published (e.g. to GitHub) and abused. The fix is per-key caps and anomaly flagging on geographic or volume spikes, on top of key rotation. velocity + anomaly FLAG would have rejected or flagged this transaction before any money moved.

Per-transaction cap
A single runaway purchase, a fat-finger API call, or an attacker testing how much they can move at once.
max_amount_usd: 500
Velocity limit
Infinite retry loops and credential-abuse bursts before the dollars pile up.
max_per_minute: 20

Don't let this happen to your agents

sipi.bot evaluates every transaction an autonomous agent proposes and returns APPROVED, BLOCKED, or FLAGGED in under 5ms — before the money moves. Self-host the MIT core free, or use the hosted dashboard with human-in-the-loop approvals.

What happened

A student was billed $55,444.78 on Google Cloud after a Gemini API key was leaked through a public GitHub repository and abused.

The root cause was classified as Leaked / stolen credential. An API key was published (e.g. to GitHub) and abused. The fix is per-key caps and anomaly flagging on geographic or volume spikes, on top of key rotation.

This is one of 14 documented incidents in the open registry. Every entry is sourced to a public URL; amounts and dates are as reported by the source.

Related incidents

Leaked credentials

Leaked Gemini API key led to a $55,444.78 Google Cloud bill

Google (Gemini) · 2025
$55,444.78 →