
One of us: $17k Gemini API spending fraudolent spike overnight
Still investigating.
What probably happened:
A project of mine was using an old Google Map API Key. Because the old key lived on the same Google Cloud project, Google's backend infrastructure automatically and silently upgraded the public Maps key to have full access to Gemini.
As described by: http://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
Key was probably scraped by the app bundle.
I already opened a case and waiting for reponse. What do you suggest me? Cannot afford the bill. Solo developer.