Hi all,
I need urgent help from the Gemini API team. My production service is completely down due to the after-effects of an API key compromise, even though I’ve already secured the project.
What happened:
- My Gemini API key was compromised. Someone ran up €271.48 of usage on my project — far beyond my normal usage (I have never used anywhere near this much).
- As soon as I discovered it, I revoked the compromised API keys, created a new restricted key, and deleted the orphaned service accounts left behind by the old keys.
- I have also reported the unauthorized charges to billing support.
Current state — two blockers:
- In AI Studio, my project now shows status “Compromised” (orange badge on the Projects page), and requests are failing with 429 RESOURCE_EXHAUSTED errors.
- I’m also getting this message:
“You’ve reached the billing account monthly spend cap and service has been paused.”
The spend that consumed the cap was the fraudulent usage itself — so the attacker’s traffic has both flagged my project and burned my entire monthly cap, and now my legitimate production traffic is locked out.
Project details:
- Project: gen-lang-client-00356955..
- Billing tier: Tier 1 · Prepay
- Compromised keys
- Unauthorized spend: ~€271.48
What I’m asking:
- How do I get the “Compromised” status removed now that the project is secured? I don’t see a clear remediation/appeal flow.
- Can the spend cap be reset or the pause lifted, given the cap was consumed by unauthorized usage and not by me?
- Is the correct place for the refund/adjustment of the €270 the billing support case, or is there a separate process for compromised-key incidents?
This is a production application with real users affected, so any pointers to the right escalation path would be hugely appreciated. Happy to provide logs, invoices, or any verification needed.
Thanks in advance!