ADVERTISEMENT

Google API keys keep working for up to 23 minutes after you delete them

When Gemini users delete Google API keys, those keys remain active for up to 23 minutes, giving attackers time to abuse them to dump data, cache conversations, and make API calls. Google “won’t fix” the “known property of the system” and doesn’t see it as a security issue, Aikido Security researchers said.

Gemini AI attack

Image by Cybernews

Ernestas Naprys
Ernestas Naprys Senior Journalist
May 22, 2026 2 min read
jurgita justinasv Izabelė Pukėnaitė vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.

Check if your data has been leaked

Find out if your email, phone number or related personal information might have fallen into the wrong hands.
18,611,353,922
Breached accounts
36,030
Breached websites
ADVERTISEMENT

Google “won’t fix” it


ADVERTISEMENT