Skip to content
Tech News
← Back to articles

€54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs

read original get Firebase Security Monitoring Tool → more articles
Why This Matters

This incident highlights the risks of unintentional API abuse and significant cost spikes when enabling new AI features in cloud services. It underscores the importance of implementing robust safeguards and monitoring to prevent unexpected charges, which is crucial for both developers and the broader tech industry. Consumers and companies must stay vigilant as API security and cost management become increasingly vital in AI-driven cloud environments.

Key Takeaways

Hello,

We are looking for guidance regarding an unexpected €54,000+ Gemini API charge that occurred within a few hours after enabling Firebase AI Logic on an existing Firebase project.

Background:

We created the project over a year ago and initially used it only for Firebase Authentication. Recently, we added a simple AI feature (generating a web snippet from a text prompt) and enabled Firebase AI Logic.

What happened:

Shortly after enabling this, we experienced a sudden and extreme spike in Gemini API usage. The traffic was not correlated with our actual users and appeared to be automated. The activity occurred within a short overnight window and stopped once we disabled the API and rotated credentials.

Additional observations:

We had a budget alert (€80) and a cost anomaly alert, both of which triggered with a delay of a few hours

By the time we reacted, costs were already around €28,000

The final amount settled at €54,000+ due to delayed cost reporting

... continue reading