A Free API Key Still Needs a Budget Boundary
Attackers used a key stolen from an exposed AI dashboard for three weeks and consumed model credits worth about $600,000. The useful lesson is to make every experimental key narrow, temporary, visible, and cheap to lose.