A weird thing happened this week that feels small in implementation and huge in implication.
For years, Google told developers that many API keys were not secrets. You could put them in frontend code for things like Maps and Firebase. That was normal. Then Gemini entered the picture, and according to Truffle Security, thousands of those same keys suddenly became valid for sensitive AI endpoints, including access to uploaded files and cached content in some projects.


