Skip to content
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

Theregister September 1, 2026

The model provider gave METR the credits for free. An actual customer would not have been so lucky

security Researcher shows how Claude Code can be tricked simply by asking it to summarize a website

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website

virtualization Broadcom pledges to lock down open source Python, Java libraries

Broadcom pledges to lock down open source Python, Java libraries

science German-Japanese researchers invent electricity-free tech that could cool datacenters

German-Japanese researchers invent electricity-free tech that could cool datacenters

NETWORKS A lot of datacenter networks are run by absolute clowns. Not Amazon's

A lot of datacenter networks are run by absolute clowns. Not Amazon's

ai and ml OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth $600,000.

METR (short for Model Evaluation and Threat Research) found no evidence that the attackers accessed sensitive information in either incident, and the org said it investigated both with security experts.

METR researchers worked with OpenAI to investigate how its agents hacked Hugging Face , and on Monday, it disclosed two of its own security snafus.

“In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” the nonprofit disclosed in a Monday report . “In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.”

From fail-open bug to model-credit theft

The March incident involved a METR researcher who didn’t have access to sensitive information - including model data and credentials, as well as information model architectures, training, and release dates. The researcher used agents running on a personal EC2 instance that was “intentionally” left publicly accessible behind Google authentication. The instance contained an API key for METR’s public models account.

According to METR’s account, a “vibe-coded app” included a fail-open bug that disabled authentication, and this exposed the system to the public internet for several days.

“We suspect that the attacker found the instance by looking through recently-registered websites (e.g. in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,” the AI research org wrote.

Once the attacker found the app, they prompted an agent to reveal its model provider API key, then added an SSH key to maintain persistent access, and over the three weeks used the stolen credentials to consume API credits on public models worth $600,000. Luckily for METR, the unnamed model developer had given the credits to the nonprofit for free.

How do you not notice the 'large illicit usage?'

METR does answer the question on everyone’s mind in the report: Why its researchers didn’t notice the “large illicit usage?”

There are several reasons for this. First, the model testing operation regularly runs evaluations that use a lot of tokens, and this means the organization is “very acclimated to getting lots of weird rate limit and API errors.” So the high usage didn’t look that out of the ordinary.

Plus, since the tokens were free, METR didn’t accrue a large bill, and at the time there was no way to put a spending limit on keys like the one that was stolen.

In response to the March incident, METR says it improved its security infrastructure, protocols, and review process, and will continue to invest in security. To this end, it also hired a security lead, and plans to add more security staff.

Crims used agents to try to access frontier models

The second incident happened in early May, when “METR became the target of a sustained external attack campaign.”

After being “tipped off” that attackers who appeared financially motivated may have been trying to gain illicit access to frontier models, METR watched the intruders probe its publicly accessible infrastructure. They also used agents to find ways to gain initial access, including automated vulnerability discovery, credential stuffing against authentication providers, attempting OAuth token grants, scanning newly deployed services, and phishing attempts.

At the same time, METR unintentionally “exposed a read-only SQL query mechanism via our public transcript viewer.” While queries were scoped to public data by default, a bug allowed access to unpublished evaluation data, and “some sensitive model data was accidentally included in this database.” However, there’s no evidence that the attacker found the exploit or accessed any non-public data, according to the model testing body.

An independent bug hunter discovered the vulnerability and reported it to METR, which paid the researcher a bounty, and took the API offline.

In response, METR says it now uses an isolated production environment for public-facing applications that is separate from its internal infrastructure.®

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

The model provider gave METR the credits for free. An actual customer would not have been so lucky

Firefox helps iPhone users bypass ads on web sites while making money showing its own ads

Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default

Platform Engineering 2.0: your platform was built for a different era. AI just exposed it

PARTNER CONTENT: Platform engineering won the argument. Now it has to grow up fast and evolve for the AI era.

Anthropic pledges to try harder to keep models under control, asks partners to chip in

Security ... this time it will be different

The teen Bill Gates has answers to the AI-pocalypse the 70-year-old Gates has forgotten

Hacking education to thrive in the AI world is the first and best step in keeping control

Oracle pins hopes on 'Star Wars' productivity jump to lightspeed from AI-assisted engineering

Big Red talks up superhuman coders after shedding 21,000 staff

security Researcher shows how Claude Code can be tricked simply by asking it to summarize a website

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website

virtualization Broadcom pledges to lock down open source Python, Java libraries

Broadcom pledges to lock down open source Python, Java libraries

security Security vets rally around $4 paper password books for sale in Australia

Security vets rally around $4 paper password books for sale in Australia

science German-Japanese researchers invent electricity-free tech that could cool datacenters

German-Japanese researchers invent electricity-free tech that could cool datacenters

Legal Nuisance-call blocker fined £190k for being a nuisance caller

Nuisance-call blocker fined £190k for being a nuisance caller

AI and ml Apple defies memory shortage with new Mac minis

Apple defies memory shortage with new Mac minis

Security Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks The model provider gave METR the credits for free. An actual customer would not have been so lucky

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

The model provider gave METR the credits for free. An actual customer would not have been so lucky

ai and ml Anthropic pledges to try harder to keep models under control, asks partners to chip in Security ... this time it will be different

Anthropic pledges to try harder to keep models under control, asks partners to chip in

Security ... this time it will be different

SYSTEMS Nvidia is building an IP licensing empire on the back of NVLink Even when you think you're not buying Nvidia, you might still be buying Nvidia

Nvidia is building an IP licensing empire on the back of NVLink

Even when you think you're not buying Nvidia, you might still be buying Nvidia

ai and ml Energy biz SSE smacked around in court by a guy and AI Company's three year pursuit of debt from non-existent address ended by Oxford judge

Energy biz SSE smacked around in court by a guy and AI

Company's three year pursuit of debt from non-existent address ended by Oxford judge

security Industry that built the problem offers to sell you the solution 100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses

Industry that built the problem offers to sell you the solution

100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

Debian votes to let contributors code with AI Disclosure optional, quality mandatory

Debian votes to let contributors code with AI

Disclosure optional, quality mandatory

LibreOffice 26.8 is out – local first, and with no AI It looks a bit clunky, but it does the job – and on your own computer

LibreOffice 26.8 is out – local first, and with no AI

It looks a bit clunky, but it does the job – and on your own computer

Keepers of Noble Numbats to be offered a Resolute Racoon: Ubuntu 26.04.1 is coming GRUB's up for furry new update

Keepers of Noble Numbats to be offered a Resolute Racoon: Ubuntu 26.04.1 is coming

GRUB's up for furry new update

AROS, the FOSS recreation of AmigaOS, comes to Raspberry Pi Plus: new official Amiga-branded hardware is coming

AROS, the FOSS recreation of AmigaOS, comes to Raspberry Pi

Plus: new official Amiga-branded hardware is coming

Emperor Penguin Linus Torvalds banishes a bug – with a bot The lad himself finds and fixes a tricky one… or does he?

Emperor Penguin Linus Torvalds banishes a bug – with a bot

The lad himself finds and fixes a tricky one… or does he?

FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash another Word up

FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash another