Skip to main content
Question

Production project suspended after 400x Gemini API cost spike from leaked key.,

  • September 7, 2026
  • 0 replies
  • 7 views

taebin
Forum|alt.badge.img

Looking for guidance on a suspension case.

Our project was shut down on Sep 7 under the hijacked-resources policy.
The trigger appears to be a billing anomaly on Gemini API — daily cost
jumped to roughly 400 times our normal baseline within a single day.
None of that traffic came from us, so we assume a key of ours ended up
somewhere it shouldn't have.

What we've done so far: every user-managed service account key in the
project is gone, and every API key including the Gemini one is gone.
Nothing left to rotate on that front. IAM stayed reachable long enough
for us to finish that part.

What we can't do: anything requiring project APIs. Audit log review,
Secret Manager rotation, checking for resources we didn't create — all
of it returns CONSUMER_SUSPENDED.

The appeal went in the same evening, plus the separate suspension
inquiry form. No decision yet.

Two questions for anyone who's been through this:

Is there any way to learn which credential Google actually flagged?
Knowing the exposure path would help us close it properly rather than
guessing.

And for those whose projects were reinstated — did anything in
particular seem to move it along, or was it purely waiting?

This runs our internal operations data, so the outage is affecting
daily work across several teams.