They've updated that documentation significantly since thousands of projects were issued automatically generated Firebase API keys, pre-Gemini. See this version from Oct 2022: https://web.archive.org/web/20221001052713/https://firebase....
Back then, they did not automatically restrict those keys to only Firebase-related APIs.
So yes, if you read the documentation as it exists today it's much more clear what they're trying to prevent, but this is only after this issue has become more apparent.