Instinct TasksUnofficial guide

Money · Community report

Dispute a cloud bill after a leaked API key

Dispute a cloud bill after a leaked API key. Find the abused key and the abnormal usage, and ask the provider to waive the charges.

What you can get

Reaches your accounts Creates or changes things in accounts you connect, with your approval.

  1. It does

    • Reads billing emails and the cloud account's usage
    • Drafts a dispute and sends it only after your approval
    • Follows up on the provider's questions; does not pay or settle anything
  2. It stops and asks

    • Before it looks: give the go-ahead to read the billing emails and account, as in the reported case.
    • Before disputing: revoke or rotate the key yourself.
    • Before sending: approve the dispute and the evidence it cites.
  3. You approve

    • Your approval before the dispute is sent
    • No authority to pay, settle or close the account

Derived from this task's own brief and steps, not from the source.

Illustration — suggested task flow, not an execution result
  1. Give the go-aheadStops for your approval

    Read access to billing emails and account usage.

  2. Find the key and usage

    Key, dates and figures compared with your normal pattern.

  3. Revoke the keyStops for your approval

    You stop the abuse before any dispute.

  4. Approve and send the disputeStops for your approval

    Evidence-based claim; follow-ups logged.

Editorial, not from the source

Works when

  • A cloud bill shows usage you did not make and you suspect a leaked key.
  • You have been ignoring billing emails because the console is hard to follow.
  • You want a clear dispute with evidence rather than a vague complaint.

Does not work when

  • The usage was yours and the bill is simply higher than you expected.
  • You have not revoked the key yet; do that first.
  • You want the bill paid to make the emails stop.

Dispute a cloud bill after a leaked API key: review template

A dispute log. It does not establish that the provider will waive any charge.
ItemEvidenceStatus
[Key][Key name or ID and project][Revoked on date]
[Abnormal usage][Dates and usage figures from the account][Compared with normal]
[Dispute][Date sent and provider reply][Waived, refused or pending]

The source case

On X, @os7borne reports that a Gemini API key leaked in May and was used overnight to generate 1.5M images and tens of millions of text tokens, far beyond their normal usage, despite billing alerts and usage limits. The resulting ₹61k charge kept hitting a credit card that, by their account, already had its own limits. They could not find the unpaid bill in the Google Cloud console and started ignoring the emails. After they connected their Google account, Instinct raised those emails in its initial scan; with their go-ahead it found the abused key and the abnormal usage, drafted a dispute, sent it and offered to follow up. They say Google Cloud replied 48 hours later and waived the ₹61k. Checked on 2026-09-24; one individual report, not evidence of how any provider will treat a dispute.

A public report by someone outside this library. Not independently reproduced here.

From the source

Source excerpt

In may one of my Gemini api keys leaked and someone started abusing it. Overnight the key was used to generate 1.5M images and tens of millions of text tokens. Way beyond my usage patterns. ... Recently I connected my Google account to instinct and in its initial scan it said this email’s showing up, it can have a look at it. I gave it a go ahead, it found this abused api key and abnormal usage, said it’ll draft the dispute claim, send it to GCP and follow up if there’s any queries. Lo and behold, 48 hours later GCP replied, 61k waived.

@os7borne · Read it at the source · checked

Quoted from the original posts. Not written by this guide, and not a result produced here.

Suggested prompt

Bring Provider billing emails, The period of the unusual usage, Your normal monthly usage, roughly. Acts Reads billing emails and the cloud account's usage. Drafts a dispute and sends it only after your approval. Follows up on the provider's questions; does not pay or settle anything. Source community report, checked 2026-09-24.

Written by this guide as a starting point, not quoted from the source. Your edits stay in this browser.

Other ways to ask

Editorial rewrites of the brief above, for a different emphasis. Copy them separately.

What you need

Editorial, not from the source

You supply

  • Provider billing emails
  • The period of the unusual usage
  • Your normal monthly usage, roughly

Connected

  • Your email
  • Read access to the cloud account's billing and usage

How to try it

Editorial, not from the source

  1. Collect the provider's billing emails and the period the unusual charges cover.
  2. Have the agent find the key and the usage that does not match your normal pattern, and show you what it found.
  3. Revoke or rotate the key yourself, so the abuse stops before anything else happens.
  4. Approve a dispute that states the leak, the dates, the usage and your normal pattern, and have it sent through the provider's billing support.
  5. Follow up on any questions, and check the account balance once the provider replies.

Stop the abuse before you argue about it

The report behind this page starts in May, when one of @os7borne's Gemini API keys leaked and someone used it overnight to generate 1.5M images and tens of millions of text tokens. By their account billing alerts and usage limits were already set, and the charge still arrived. Before any dispute, the first job is to revoke or rotate the key so the usage stops, and to check whether any other keys in the same project were exposed. The post does not say how the key leaked or when it was revoked, so this page cannot tell you either. What it does show is that alerts and limits on the provider side were not a guarantee, and that a separate limit on the card, which the user had set, stopped the charge from going through.

Let it read what you have been ignoring

The most familiar part of the post is the avoidance. The user could not find the unpaid bill in the Google Cloud console, could not find it by searching for unpaid bills either, and started ignoring the emails. After they connected their Google account, Instinct raised those emails in its initial scan and offered to look. With a go-ahead, it found the abused key and the abnormal usage. That order matters: the agent asked before digging into billing, and the evidence came from the account itself rather than from a guess. Ask for the key, the dates and the usage figures to be shown to you, and compare them with your normal monthly pattern before anything is written to the provider.

A dispute with evidence, then follow-up

A dispute is strongest when it reads like a record: the key involved, the period of abnormal usage, what that usage was, what your usage normally looks like, and when the key was revoked. In the reported case the agent drafted the claim, sent it to Google Cloud and said it would follow up on any questions; the user says Google Cloud replied 48 hours later and waived ₹61k. That is one provider and one outcome. Read the draft before it is sent, since it speaks for you, and keep every reply with its date. Paying the bill to make the emails stop, or accepting a partial settlement, are decisions to make yourself rather than steps an agent should take in the middle of a dispute.

Limits and confirmation points

  • One attributed report. It shows one provider waiving one bill; it does not establish that providers waive leaked-key charges.
  • The report does not say how the key leaked or whether it was revoked. Stopping the abuse is your first job, before any dispute.
  • In the report, billing alerts and usage limits did not prevent the charge. Do not treat them as protection.
  • The dispute speaks for you to the provider. Nothing should be sent, and no payment or settlement agreed, without your approval.

Editorial, not from the source

  • Before it looks: give the go-ahead to read the billing emails and account, as in the reported case.
  • Before disputing: revoke or rotate the key yourself.
  • Before sending: approve the dispute and the evidence it cites.

Editorial, not from the source

The unpaid bill cannot be found in the console
Start from the billing emails instead; they usually name the billing account and the invoice. The reported user could not find it in the console either.
The provider asks for more information
Answer with the usage records and the date you revoked the key. Keep each reply with its date.
The card keeps being charged
Check with your card issuer what limits or blocks are available while the dispute is open. The reported user already had card limits in place.

Common questions

Can Instinct dispute charges from a leaked API key?

One user reports that it found the abused key and the abnormal usage, drafted a dispute, sent it, and that the provider waived ₹61k 48 hours later. This directory has not reproduced it.

What should I do first?

Revoke or rotate the key so the usage stops. A dispute does not stop further charges.

Do billing alerts and usage limits prevent this?

Not reliably. In the reported case they were in place and the charge still arrived; a separate limit on the card stopped it from being paid.

What should the dispute include?

The key, the dates, the abnormal usage, your normal usage for comparison, and when the key was revoked.

Should I just pay the bill?

That is your decision, but paying first can make a waiver harder to argue. Decide before anything is agreed with the provider.

Next in Money

  • Find forgotten subscriptions A list of recurring subscriptions, upcoming renewals and charges to review.
  • Lower your internet bill A lower quoted rate on the same service, or a number and a script for you to finish the call, with any offer checked by you before it is accepted.
  • Chase a refund that never arrived A traced refund with its reference number, a record of who was contacted and what each said, and either the credit confirmed or a clear next step.

Get recurring task recommendations — ask your own agent to check for relevant updates.