You just discovered your Google API key was leaked. Maybe it showed up in a GitHub search. Maybe a secret scanner flagged it. You panic, open the Google Cloud Console, and delete it.
Done. Crisis averted.
Except it isn't.
That key is still working. For the next 23 minutes, an attacker can keep using it — making requests, racking up your cloud bill, or accessing data you thought was already cut off.
This is not a theoretical risk. It's a documented vulnerability that Google initially dismissed as "expected behavior" — before later upgrading it to a P0/S0 critical bug.






