WeSearch

Threat hunters find Google API keys still usable 23 minutes after deletion

O'Ryan Johnson· ·5 min read · 0 reactions · 0 comments · 14 views
#security#google#api#billing#developers
Threat hunters find Google API keys still usable 23 minutes after deletion
⚡ TL;DR · AI summary

Security researchers have found that Google API keys can remain usable for up to 23 minutes after deletion. This creates a significant risk for developers, as attackers can exploit this window to incur charges or access sensitive data. The issue has been exacerbated by Google's billing policy changes, which can lead to unexpectedly high costs for victims.

Key facts
Original article
The Register · O'Ryan Johnson
Read full at The Register →
Opening excerpt (first ~120 words) tap to expand

(function() { let windowUrl = window.location.href; windowUrl = windowUrl.substring(windowUrl.indexOf('?') + 1); let messageElement = document.querySelector('.shareableMessage'); if (windowUrl && windowUrl.includes('code') && windowUrl.includes('expires')) { messageElement.style.display = 'block'; } })(); DevOps Threat hunters find Google API keys still usable 23 minutes after deletion Plenty of time for bad actors to grab data or hit you with a giant bill O'Ryan Johnson O'Ryan Johnson Published thu 21 May 2026 // 21:23 UTC You know your Google API key has leaked so you rush to disable it before bad actors can start running up charges on your account.

Excerpt limited to ~120 words for fair-use compliance. The full article is at The Register.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from The Register