
Developer burned €54k in 13 hours via exposed Firebase key to Gemini API
Hacker News·1mo·zanbezi
A maker left an unrestricted Firebase browser key public, which attackers used to hammer Google's Gemini API, generating a massive bill in just over half a day. It's a sharp reminder that browser keys need API restrictions and quota limits, not just secret key rotation—especially when pointing at costly LLM endpoints.
Original story
Read the original on Hacker NewsRelated stories
SaaS
BigBalli ships a simple move reminder tool to fight desk sedentary habitsHacker News·1h·BigBalli
AI
Local RAG + knowledge graph agent built by solo dev, no cloud requiredHacker News·1h·gabriel_oauth