Skip to main content
← Back to sources

Unrestricted Firebase Browser Key Leads to €54K Gemini API Billing Spike in 13 Hours

Published 2026-04-16AI Regulation and GovernanceHigh

Summary

A developer reported on the Google AI Developers Forum that enabling Firebase AI Logic on an existing Firebase project resulted in an unexpected €54,000+ Gemini API charge accumulated in just 13 hours. The root cause appears to be an unrestricted Firebase browser API key that was exposed client-side, allowing unauthorized third parties to make Gemini API requests against the project's billing account without any API restrictions in place. This incident highlights a critical and growing risk in

Alignment: Reinforces current position
Related Positions: ai-governance-and-risk.md, ai-infrastructure-strategy.md, enterprise-ai-delivery.md
firebasegemini-apiapi-key-securitybilling-spikecloud-cost-managementai-governancegoogle-cloudapi-restrictionsenterprise-riskai-infrastructure
Unrestricted Firebase Browser Key Leads to €54K Gemini API Billing Spike in 13 Hours — Intelligence — Agentic Developer Tools Radar · Signal