A developer who introduced AI features into an existing Firebase project reported receiving an unexpectedly high bill for the Gemini API. The charges exceeded 50,000 euros, occurring over a period of just 13 hours [Hacker News].
SecurityPricing & LimitsFirebaseGemini
Over 50,000 Euros Billed to Gemini API via Unrestricted Firebase API Key
This article is a translation. Read the Japanese original
This traffic is believed to have been caused by automated access rather than actual users. The activity ceased after the developer disabled the API and updated the credentials.
Google Cloud support determined the charges to be valid, as the requests originated from the project. The application for a billing adjustment was rejected [Hacker News].
In response, a Google representative suggested countermeasures such as setting spend caps and adopting a prepaid system. They also stated that they intend to disable the use of unrestricted API keys for the Gemini API [Hacker News].
The representative advised avoiding the placement of keys within client-side code. They noted that a feature is provided to automatically disable keys for security reasons if they are detected on the public web [Hacker News].
Source: €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs(HN 400pt・296コメント) (HN Search (backfill), 2026-04-16)