Back Theregister Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
The model provider gave METR the credits for free. An actual customer would not have been so lucky
security Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
virtualization Broadcom pledges to lock down open source Python, Java libraries
Broadcom pledges to lock down open source Python, Java libraries
science German-Japanese researchers invent electricity-free tech that could cool datacenters
German-Japanese researchers invent electricity-free tech that could cool datacenters
NETWORKS A lot of datacenter networks are run by absolute clowns. Not Amazon's
A lot of datacenter networks are run by absolute clowns. Not Amazon's
ai and ml OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth $600,000.
METR (short for Model Evaluation and Threat Research) found no evidence that the attackers accessed sensitive information in either incident, and the org said it investigated both with security experts.
METR researchers worked with OpenAI to investigate how its agents hacked Hugging Face , and on Monday, it disclosed two of its own security snafus.
“In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” the nonprofit disclosed in a Monday report . “In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.”
From fail-open bug to model-credit theft
The March incident involved a METR researcher who didn’t have access to sensitive information - including model data and credentials, as well as information model architectures, training, and release dates. The researcher used agents running on a personal EC2 instance that was “intentionally” left publicly accessible behind Google authentication. The instance contained an API key for METR’s public models account.
According to METR’s account, a “vibe-coded app” included a fail-open bug that disabled authentication, and this exposed the system to the public internet for several days.
“We suspect that the attacker found the instance by looking through recently-registered websites (e.g. in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,” the AI research org wrote.
Once the attacker found the app, they prompted an agent to reveal its model provider API key, then added an SSH key to maintain persistent access, and over the three weeks used the stolen credentials to consume API credits on public models worth $600,000. Luckily for METR, the unnamed model developer had given the credits to the nonprofit for free.
How do you not notice the 'large illicit usage?'
METR does answer the question on everyone’s mind in the report: Why its researchers didn’t notice the “large illicit usage?”
There are several reasons for this. First, the model testing operation regularly runs evaluations that use a lot of tokens, and this means the organization is “very acclimated to getting lots of weird rate limit and API errors.” So the high usage didn’t look that out of the ordinary.
Plus, since the tokens were free, METR didn’t accrue a large bill, and at the time there was no way to put a spending limit on keys like the one that was stolen.
In response to the March incident, METR says it improved its security infrastructure, protocols, and review process, and will continue to invest in security. To this end, it also hired a security lead, and plans to add more security staff.
Crims used agents to try to access frontier models
The second incident happened in early May, when “METR became the target of a sustained external attack campaign.”
After being “tipped off” that attackers who appeared financially motivated may have been trying to gain illicit access to frontier models, METR watched the intruders probe its publicly accessible infrastructure. They also used agents to find ways to gain initial access, including automated vulnerability discovery, credential stuffing against authentication providers, attempting OAuth token grants, scanning newly deployed services, and phishing attempts.
At the same time, METR unintentionally “exposed a read-only SQL query mechanism via our public transcript viewer.” While queries were scoped to public data by default, a bug allowed access to unpublished evaluation data, and “some sensitive model data was accidentally included in this database.” However, there’s no evidence that the attacker found the exploit or accessed any non-public data, according to the model testing body.
An independent bug hunter discovered the vulnerability and reported it to METR, which paid the researcher a bounty, and took the API offline.
In response, METR says it now uses an isolated production environment for public-facing applications that is separate from its internal infrastructure.®
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
The model provider gave METR the credits for free. An actual customer would not have been so lucky
Firefox helps iPhone users bypass ads on web sites while making money showing its own ads
Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default
Platform Engineering 2.0: your platform was built for a different era. AI just exposed it
PARTNER CONTENT: Platform engineering won the argument. Now it has to grow up fast and evolve for the AI era.
Anthropic pledges to try harder to keep models under control, asks partners to chip in
Security ... this time it will be different
The teen Bill Gates has answers to the AI-pocalypse the 70-year-old Gates has forgotten
Hacking education to thrive in the AI world is the first and best step in keeping control
Oracle pins hopes on 'Star Wars' productivity jump to lightspeed from AI-assisted engineering
Big Red talks up superhuman coders after shedding 21,000 staff
security Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
virtualization Broadcom pledges to lock down open source Python, Java libraries
Broadcom pledges to lock down open source Python, Java libraries
security Security vets rally around $4 paper password books for sale in Australia
Security vets rally around $4 paper password books for sale in Australia
science German-Japanese researchers invent electricity-free tech that could cool datacenters
German-Japanese researchers invent electricity-free tech that could cool datacenters
Legal Nuisance-call blocker fined £190k for being a nuisance caller
Nuisance-call blocker fined £190k for being a nuisance caller
AI and ml Apple defies memory shortage with new Mac minis
Apple defies memory shortage with new Mac minis
Security Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks The model provider gave METR the credits for free. An actual customer would not have been so lucky
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
The model provider gave METR the credits for free. An actual customer would not have been so lucky
ai and ml Anthropic pledges to try harder to keep models under control, asks partners to chip in Security ... this time it will be different
Anthropic pledges to try harder to keep models under control, asks partners to chip in
Security ... this time it will be different
SYSTEMS Nvidia is building an IP licensing empire on the back of NVLink Even when you think you're not buying Nvidia, you might still be buying Nvidia
Nvidia is building an IP licensing empire on the back of NVLink
Even when you think you're not buying Nvidia, you might still be buying Nvidia
ai and ml Energy biz SSE smacked around in court by a guy and AI Company's three year pursuit of debt from non-existent address ended by Oxford judge
Energy biz SSE smacked around in court by a guy and AI
Company's three year pursuit of debt from non-existent address ended by Oxford judge
security Industry that built the problem offers to sell you the solution 100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses
Industry that built the problem offers to sell you the solution
100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Debian votes to let contributors code with AI Disclosure optional, quality mandatory
Debian votes to let contributors code with AI
Disclosure optional, quality mandatory
LibreOffice 26.8 is out – local first, and with no AI It looks a bit clunky, but it does the job – and on your own computer
LibreOffice 26.8 is out – local first, and with no AI
It looks a bit clunky, but it does the job – and on your own computer
Keepers of Noble Numbats to be offered a Resolute Racoon: Ubuntu 26.04.1 is coming GRUB's up for furry new update
Keepers of Noble Numbats to be offered a Resolute Racoon: Ubuntu 26.04.1 is coming
GRUB's up for furry new update
AROS, the FOSS recreation of AmigaOS, comes to Raspberry Pi Plus: new official Amiga-branded hardware is coming
AROS, the FOSS recreation of AmigaOS, comes to Raspberry Pi
Plus: new official Amiga-branded hardware is coming
Emperor Penguin Linus Torvalds banishes a bug – with a bot The lad himself finds and fixes a tricky one… or does he?
Emperor Penguin Linus Torvalds banishes a bug – with a bot
The lad himself finds and fixes a tricky one… or does he?
FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash another Word up
FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash another
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
