Developers’ public API keys now function as live Gemini AI credentials, enabling attackers to run costly and unauthorized operations.