API key exploitation is more than hypothetical. In a different context, a student who reportedly exposed a GCP API key on GitHub last June was left nursing a $55,444 bill (later waived by Google) ...
On February 24, 2026, India’s Ministry of Electronics and Information Technology ordered internet service providers to block access to Supabase, the popular open-source backend-as-a-service platform.