A newly disclosed issue with Google Cloud API keys reveals that deleted credentials may remain usable for up to 23 minutes, exposing projects to potential abuse even after revocation.
The finding raises concerns about delayed credential invalidation across Google’s infrastructure, particularly for sensitive services such as Gemini, BigQuery, and Google Maps APIs. According to Aikido research, deleting a Google API key does not immediately terminate its access.
Instead, revocation propagates gradually across distributed systems, creating a “revocation window” during which the key continues to authenticate requests.
Attackers with leaked keys can continue making API calls during this period because some backend servers may still accept deleted keys, causing inconsistent enforcement.
The issue becomes more severe when high-value services are enabled. If a compromised key has access to Google’s Gemini API, attackers may:
Similar behavior was observed across other services, including the BigQuery and Maps APIs, indicating that the delay is tied to API key infrastructure rather than individual services.
Researchers conducted controlled experiments over multiple days:
Results showed unpredictable success rates. For example, one minute after deletion, some trials still saw up to 79% of requests succeed, while others dropped to as low as 5%.
This inconsistency makes it difficult to determine when a key is truly invalid. Tests across multiple Google Cloud regions revealed uneven propagation:
Interestingly, some distant regions rejected deleted keys faster than closer ones, suggesting that routing, caching, or infrastructure differences influence revocation timing.
The Google Cloud Console does not clearly indicate that a deleted key is still active. Instead:
This aggregation complicates incident response, as security teams cannot easily attribute activity to a specific deleted key.
Not all Google credentials exhibit the same delay:
This disparity suggests that faster revocation is technically feasible but not implemented for standard API keys.
Aikido researcher Joe Leon said Google marked the issue as “won’t fix,” describing the delay as expected behavior in eventually consistent systems rather than a security flaw.
While Google documents eventual consistency in IAM systems, it does not explicitly warn users about delayed API key revocation.
Delayed revocation contradicts typical expectations that deleting credentials immediately blocks access. Even short delays can be exploited, as prior cloud security research demonstrates.
For organizations using Google Cloud, this creates several risks:
Until changes are implemented, security teams should adjust their response strategies:
This discovery highlights a broader challenge in cloud security: balancing scalability with strict authentication guarantees. In the case of Google API keys, the current model leaves a critical gap that attackers can exploit during the revocation window.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…