https://trufflesecurity.com/blog/google-api-keys-werent-secr...
> Even Google themselves had old public API keys, which they thought were non-sensitive, that we could use to access Google’s internal Gemini.
This is just a classic slow clap here for Cloud.
I did something or another with a google API years ago, and am not looking forward to a random surprise bill. They don't have my credit card, so maybe that'd solve the problem. On the other hand, they could hold a gmail account hostage.