$60K Billed in 13 Hours: Why Leaked Firebase Keys Keep Killing AI-Built Apps
A Japanese dev just got billed roughly $60,000 (~9 million yen) in 13 hours because a Google API key leaked from their Firebase + Gemini app. I saw the post trending on Qiita this morning and my stomach dropped — not because it's a new story, but because I've seen the exact same mistake every single week while building CodeHeal, my security scanner for AI-generated code. The key was exposed. The key had no referrer restriction. An attacker found it, pointed it at Gemini, and burned through the...
Original Source
Read the full article at Dev →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.