Google API Keys Remain Active for Up to 23 Minutes After Deletion

Google API Keys Remain Active for Up to 23 Minutes After Deletion

First seen 21 May 2026, 21:35 UTC DarkreadingTheregisterwww.offensai.comFeeds2.FeedburnerCybersecuritynews+2 88% similarity 66.0

Article Content

Browse articles
ThreatCluster

Research by Aikido Security reveals that Google API keys can remain active for up to 23 minutes post-deletion, contrary to user expectations of immediate revocation. This delay allows attackers with leaked keys to continue accessing sensitive services, including Gemini, during this window. Aikido's tests showed a median revocation window of around 16 minutes, with significant variability based on server location. The findings highlight a critical vulnerability in Google's infrastructure, as attackers can exploit this delay to run up charges or exfiltrate sensitive data. Google has not provided a fix for this issue, which poses a serious risk to organizations relying on API keys for access control. The problem is compounded by Google's billing policies that can lead to unexpected charges for users. This situation mirrors a previously reported issue with AWS access keys, where a four-second window allowed for similar exploitation.

Key Points: • Google API keys can remain valid for up to 23 minutes after deletion. • Attackers can exploit this delay to access sensitive data and incur unexpected charges. • Google has not addressed this vulnerability, leaving users at risk.

ThreatCluster AI

Timeline

2026-05-21
Aikido Security publishes research on Google API keys
Aikido Security's tests reveal that Google API keys remain active for up to 23 minutes after deletion, posing a significant security risk.
Darkreading
2026-05-21
Google API keys revocation window analyzed
Research shows that the revocation window for Google API keys averages 16 minutes, allowing attackers to misuse deleted keys.
Aikido.dev
2026-05-21
Threat hunters report on Google API key vulnerabilities
Researchers confirm that deleted Google API keys can still be used for up to 23 minutes, creating a significant security gap.
The Register
2026-05-22
Ongoing risk from Google API key vulnerabilities
The issue with Google API keys remains unresolved, continuing to expose users to potential abuse and unexpected charges.
Cybersecuritynews

Community

Browse all →