Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds

https://hackread.com/wp-content/uploads/2026/05/deleted-google-api-keys-active-23-minutes-1024x576.png

A new study conducted by the cybersecurity firm Aikido Security reveals that deleted Google API keys stay active and can continue authenticating successfully for up to 23 minutes after they are removed. The results were obtained after running 10 controlled trials over two days to measure the delay.

Key Findings

An API key is a string of data used to authenticate requests between software applications. According to researchers, the Google Cloud Platform (GCP) console shows the key as deleted immediately. However, tests showed that the keys actually take an average of 16 minutes to stop working completely, with the longest delay lasting nearly 23 minutes.

During this timeframe, threat actors holding a leaked key retain full access to any enabled APIs on the project. This allows them to exfiltrate cached conversations and dump files uploaded to Gemini. They can also access BigQuery data and Maps APIs.

Why Does The Issue...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/b2J8oM95BkJa6VF8Ut77BU-1920-80.jpg

The Witcher 3: Wild Hunt lead quest designer recalls the moment he suggested that one character be killed off, says the team's reaction was 'wide eyes and silence' — 'The weight of it is exactly what the act needs'

* The Witcher 3: Wild Hunt lead quest designer Paweł Sasko says his suggestion to kill off a certain character shocked the team * Sasko argued that "the weight" of the scene was exactly what the act needed * He says the team ran into many technical difficulties during the Battle

https://assets.bwbx.io/images/users/iqjWHBFdfxIU/idAI1qKpM9tY/v0/1200x799.jpg

Source: smart ring maker Oura filed confidentially for a US IPO, set for later in 2026; SF- and Finland-based Oura had an $11B valuation in September 2025

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. The Private AI That Remembers — Anuma is the all-in-one AI platform with private, portable memory.