Google Cloud developers who delete compromised API keys for Gemini face a 23-minute window during which attackers can continue using those credentials to access models and exfiltrate data, according to research from security firm Aikido published this week. During that window, success rates for authentication requests reached 90% in some minutes, and attackers used the time to pull cached conversation data and files from Gemini accounts. Google's newer credential formats revoke in 5 seconds for service account keys and 1 minute for Gemini's AQ-prefixed keys, both running at Google scale.
The revocation gap sits at the center of a broader pattern documented by The Register over recent weeks. Developers across Google Cloud woke to five-figure bills after API keys originally deployed for Google Maps quietly gained access to Gemini when Google expanded their scope without clear disclosure. Rod Danan, CEO of interview-prep platform Prentus, saw his bill hit $10,138 in roughly 30 minutes. Isuru Fonseka, a Sydney-based developer, incurred charges of roughly AUD $17,000 despite believing he had a $250 spending cap in place.
What neither developer knew was that Google's automated systems had upgraded their billing tiers based on account history, raising their effective ceilings to as high as $100,000 without explicit consent. Google refunded both after The Register's initial report but told the outlet it has no plans to change its automatic tier-upgrade policy, prioritizing service continuity over enforcing users' stated budget limits.
Key facts
- 01Google Cloud's API keys for Gemini continue authenticating for up to 23 minutes after deletion, with 90% success rates in some minutes.
- 02Rod Danan incurred a $10,138 bill in roughly 30 minutes after attackers exploited his compromised API key.
- 03Google automatically raised account spending caps to $100,000 without explicit consent, overriding users' stated $250 limits.
- 04Service account API credentials revoke in 5 seconds and Gemini's newer AQ-prefixed key format takes 1 minute, both at Google scale.
- 05The average time between initial breach and next-stage handoff has dropped from 8 hours to 22 seconds.
Aikido researcher Joseph Leon noted that Google's own newer credential formats don't share the 23-minute problem. Service account API credentials revoke in about 5 seconds, and Gemini's newer AQ-prefixed key format takes about 1 minute. The 23-minute window for legacy keys is not an engineering constraint but a matter of priorities, Leon concluded in Aikido's paper.
The incidents arrive as Google Cloud COO Francis de Souza describes the broader AI security challenge facing enterprises. Speaking at an event in Los Angeles, de Souza flagged a collapse in attacker dwell time — the average interval between initial breach and handoff to the next stage of an attack has dropped from 8 hours to 22 seconds. The attack surface has expanded beyond traditional network perimeters to include models, data pipelines, agents, and prompts.
De Souza argued that security must be foundational to AI strategy, not an afterthought, and warned specifically about shadow AI, where employees adopt consumer tools without organizational oversight. He described AI-native agentic defense as the emerging answer, where organizations run agents driving their defense rather than human-led or human-in-the-loop systems. He emphasized that this has become a board-level issue, not just a security team's problem.
One threat de Souza highlighted that receives less attention is agents surfacing forgotten internal data repositories. Old SharePoint servers with outdated access controls might have been functionally invisible for years, but agents roaming an enterprise will find those data assets and expose the data on them. The expansion of the attack surface is compounded by multicloud and SaaS sprawl, making consistent security posture across clouds and models a structural challenge.
The talent gap compounds the technical gap. LinkedIn Chief Information Security Officer Lea Kissner told the New York Times this week that the industry will need people to handle the bug-pocalypse, and she does not expect AI security to reach any sustainable long-term understanding for at least several years. The gap between what platform providers are prescribing and how fast those providers are themselves adapting remains wide.
The 23-minute revocation window is a microcosm of the broader dynamic. Google has already solved the problem at scale for newer credential types, proving the technical path exists. The legacy key format remains exposed not because the engineering is impossible but because the priority has not yet shifted. Developers deleting a compromised key expect immediate revocation. The fact that attackers gain nearly half an hour of continued access turns that expectation into a liability.
Google refunded the developers in the billing-cap cases, but the automatic tier-upgrade policy remains unchanged. The company's stated rationale is preventing service outages, which means the current design assumes developers prefer uninterrupted access over enforcing their own stated spending limits. That assumption holds until a compromised key generates a $10,000 bill in 30 minutes, at which point the tradeoff inverts.
The gap between advice and implementation is not unique to Google. De Souza's recommendations about platform security, multicloud posture, and agentic defense are directionally correct, but the platform providers themselves are navigating the same transition period in real time. The 22-second dwell time de Souza cited reflects attackers moving at machine speed. The 23-minute revocation window reflects defenders still operating at human-committee speed on legacy infrastructure decisions.
The Aikido findings and the billing-cap incidents together illustrate the cost of that lag. Developers who follow best practices — monitoring for anomalies, deleting compromised keys immediately — still face exposure because the platform's revocation pipeline has not caught up to the threat model. The fix is technically solved elsewhere in Google's own infrastructure. The question is how long the legacy format remains an open window.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




