Google AI Studio API key compromised ~₹8.3 lakh in Gemini 3 Pro Image charges in less than 2 hours, days after a suspension and reinstatement. Support is investigating, looking for advice from anyone who has been through this 🙏

Opened up my billing page for GCP after my bank got in touch with me and found out that I had been charged for $6,486.81.

I keep the account associated with GCP insanely low b/c I have always worried about this nightmare scenario. I wasted so many hours setting up alerts and budgets that i think i am done with cloud services and development in general.
Now I have to look forward with resolving issues with bank and GCP billing. I have a google case support ticket open so I guess its a start. Here is how i spent my evening researching this issue.

Prompt "Research questions — please answer each with sources:

  1. Prevalence: Search Google Cloud Community forums, Reddit (r/googlecloud, r/Bard, r/GeminiAI), Hacker News, Twitter/X, and GitHub Issues for reports of unexpected Gemini API billing spikes in April–May 2026. Are others reporting the same pattern? Compile a list with dates, amounts, and links.
  2. Stolen-key resale botnets: Find documentation of the broader pattern where attackers harvest leaked LLM API keys (OpenAI, Anthropic, Google) and burn them in 24-hour bursts via image-generation endpoints. What are the known exfiltration vectors (AI Studio session compromise, browser extensions, copy-paste into third-party tools, Colab notebooks, marketplace bundles)?
  3. Google AI Studio key exposure: Are there documented cases where keys created via AI Studio (aistudio.google.com) leaked through the AI Studio UI itself, browser extensions, or Google’s own telemetry? Has Google acknowledged any such vector?
  4. Gemini 3 Pro Image / Gemini 3.1 Flash Image launch: When did these models go GA? Was there any auto-enrollment, free-tier-to-paid transition, billing-tier change, or default-quota change that hit existing API keys around the launch date? Check Google’s release notes, the Gemini API changelog, and the Vertex AI release notes.
  5. Google’s refund track record for this scenario: Search for first-person accounts of users who got refunds (full or partial) for Gemini / Vertex API abuse charges. What worked? What arguments did Google accept or reject? Specifically look for cases involving (a) keys never published publicly, (b) absence of Data Access logs, (c) IP-restriction-added-after-the-fact mitigations.
  6. The Data Access logging default-off issue: Find any public commentary — blogs, GCP community posts, security researcher writeups — about Google leaving Data Access logging off by default for generativelanguage.googleapis.com, and how that affects customer ability to investigate abuse. Is this a known structural complaint?
  7. Class action or pattern recognition: Has any consumer-protection org, security researcher, or journalist written about a wave of Gemini billing incidents tied to a specific exfiltration source or Google-side policy change?
    Output format: Structured markdown report. For each question, a short answer + bulleted evidence with full URLs. Note where you found nothing — absence of reports is itself useful data."
    That is how i found this forum and question.