Google AI Studio API key compromised ~₹8.3 lakh in Gemini 3 Pro Image charges in less than 2 hours, days after a suspension and reinstatement. Support is investigating, looking for advice from anyone who has been through this 🙏

quickly do remove the Gemini API permission for all old keys. Those old client side keys also have access

i just removed billing from all projects and deleted them. I am done with Google Cloud. The response time on this case. This organization doesn’t give 2 effs for devs that tested out their AI and gave them feedback from day 1. Oh and btw…i setup deepkseek V4 as my default model.
My experience is that it is 10x better than Gemini and Opus on coding.
Here is breakdown
Model Cost Messages Tokens
deepseek-v4-flash $1.46 1,954 221.5M
deepseek-v4-pro $1.07 554 54.1M

Hi @Mustan_lokhand

My Gemini API key got compromised and was abused . I had set a budget of 4000 rs INR. however, the bill kept blowing up to more than 1.5L within a period of 6 hours. The cost explorer showed that its due to GEMINI API key.
I have deleted the api key and disabled the gemini api in the project.

Case #7210573

Today Google charged USD 7.5k to my credit card, with another USD 6k still pending.

An API key used through AI Studio appears to have been compromised, and between roughly 12 PM and 1 PM there were around 600,000 Gemini API requests made. This usage is completely abnormal and nowhere near my regular consumption.

What concerns me most is that there seemed to be no effective protection against such an extreme spike. Hundreds of thousands of requests in a single hour should arguably trigger fraud detection, temporary throttling, spending alerts, emergency limits, or some kind of protective mechanism.

I’m now facing more than USD 13,000 in charges from activity that I did not intentionally generate and simply cannot afford to pay.

Has anyone else experienced something similar? Were you able to get the charges reviewed or reversed by Google Cloud / Gemini support?

Same exact situation here @Piyush_Agarwal. :folded_hands:

On June 25, a compromised Gemini API key on my project generated ~11,500 image requests in ~107 minutes (100% Gemini 3 Pro Image / 3.1 Flash Image), ~€1,800 in charges. My app only does text + TTS, rarely images. And like several of you, this happened days after a Trust & Safety suspension (“pirated/hijacked resources”) and reinstatement — the exact same pattern.

Google’s own anomaly detection flags it as a “major anomaly” (expected €0.36 vs €1,643 actual, >1000%), and billing support confirmed it as “fraudulent/unauthorized usage” and committed to raise an adjustment. Case #72625879.

@Mustan_lokhand happy to DM you my case ID and project ID too, if you’re consolidating these for the specialized team. This clearly looks systemic — Shekhar’s point about Gemini being attached to old client-side public keys is spot on.

Solidarity, all hoping we all get made whole. :folded_hands:

Hello @Mustan_lokhand I also have a simiar case could we please check?