> We had a budget alert (€80) and a cost anomaly alert, both of which triggered with a delay of a few hours. By the time we reacted, costs were already around €28,000. I had a similar experience with GCP where I set a budget of $100 and was only emailed 5 hours after exceeding the budget by which time I was well over it. It's mind boggling that features like this aren't prioritized. Sure it would probably make Google…
€54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
81–90 of 325 posts
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#82> We had a budget alert (€80) and a cost anomaly alert, both of which triggered with a delay of a few hours. By the time we reacted, costs were already around €28,000. I had a similar experience with GCP where I set a budget of $100 and was only emailed 5 hours after exceeding the budget by which time I was well over it. It's mind boggling that features like this aren't prioritized. Sure it would probably make Google…
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#83Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#84Can you pre-load money into your account and have that be used until it's zero, at which time you have to load more? Deepseek does it this way.
https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_wha...>
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#85[flagged]
This reads like 100% an LLM comment. by design -- the enforcement Nothing new here - what is new is the A thing before anyone noticed - another thing, billing in hours, damage in minutes. has the signal, doesn't expose the control Every one of those "exposes the signal" to me.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#86I said this when this finding was originally posted and I'll say it again: This is by far the worst security incident Google has ever had, and that's why they aren't publicly or loudly responding to it. It's deeply embarrassing. They can't fix it without breaking customer workflows. They really, really want it to just go away and six months from now they'll complete their warning period to their enterprise contracts…
It's not a security incident because it makes Google money. It's extra revenue. They are embarrassed all the way to the bank. At some point, when it appeared 2 months ago on HN and they still did nothing about it, intentionality can be assumed.
However, anyone affected should probably pollute their docket with lawsuits anyway.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#87I think the logistics of calculating cost in real time is something that is extremely hard. I don't think there is one big cloud service provider that has hard limits instead of alerts. As long as they revert the charge when notified of scenarios like this , and they have historically done so for many cases, it's fine. It's an acceptable workaround for a hard problem and the cost of doing business ( just like Credit…
Don't tote the party line.
Same reason why Azure AI only has easy rate limits by minute, not by day or week or month. Open source proxy projects do it easily tho. Think about the incentives.
Going over a hard cap by 3% would be a reasonable failure to make, not by 30000%.
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#88With EC2 / GCC credentials, I could understand going all out on bitcoin mining - but what are they asking the AI to do here that's worth setting up some kind of botnet or automation to sift the internet for compromised keys?
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#89Considering the amount of repositories on public GitHub with hard-coded Gemini API tokens inside the shared source code ( https://github.com/search?q=gemini+%22AIza%22&type=code ), this hardly comes as a surprise. Google also has historically treated API keys as non-secrets, except with the introduction of the keys for LLM inference, then users are supposed to treat those secretly, but I'm not sure everyone got that…
> Google also has historically treated API keys as non-secrets, except with the introduction of the keys for LLM inference, then users are supposed to treat those secretly This was reported a long time ago, and was supposed to be fixed by Google via making sure that these legacy public keys would not be usable for Gemini or AI. https://news.ycombinator.com/item?id=47156925 https://ai.google.dev/gemini-api/docs/troubl…
Re: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
#90> By the time we reacted, costs were already around €28,000
> The final amount settled at €54,000+ due to delayed cost reporting
So much for the folks defending these three companies that refused to provide hard spending cap ("but you can set the budget", "you are doing it wrong if you worry about billing", "hard cap it's technically impossible" etc.)