Back Infosecurity-Magazine Attackers Steal METR API Key and Burn $600,000 in AI Credits
Attackers have stolen an API key from AI safety research organization METR and used it for three weeks to consume model credits that would have been worth $600,000.
METR disclosed the incident in a security update published on Aug 31, alongside highlighting a separate attack in May in which threat actors probed its public infrastructure. It said it had found no evidence that sensitive information was accessed in either incident.
The credits had been supplied free of charge by the unnamed model developer, so the $600,000 represents their commercial value rather than a direct financial loss.
METR said the disclosure concerned external attackers rather than AI agents acting inside its evaluations, where an initial scan had found no evidence of agents hacking third parties.
Vibe-Coded App Exposed API Key
The incident began in March when a METR researcher ran agents on a personal Amazon EC2 instance made publicly accessible behind Google authentication. The vibe-coded app held an API key for METR's public models account.
A fail-open flaw silently disabled authentication, leaving the system exposed for several days. METR said it suspected the attacker had found the instance by mining certificate transparency lists for recently registered sites carrying high-signal terms relating to language models and agents.
The attacker prompted an agent to reveal the model provider API key and added an SSH key for persistence, then used the stolen credentials to consume large volumes of model credits over three weeks.
METR said the illicit usage was hard to distinguish from legitimate evaluation activity, since its researchers routinely generated high volumes of model traffic, and it had no way to cap spending on free-credit keys.
The organization revoked the researcher's access, rotated credentials, wiped the laptop and alerted the model developer. It later added spend alerts to keys where possible.
Second Attack Probed Public Infrastructure
METR said it had been tipped off in early May that it was being targeted by attackers who appeared financially motivated and may have been seeking frontier model access.
The attackers made heavy use of agents to automate vulnerability discovery, including credential stuffing, OAuth token grant attempts, scanning of new services and attempts to phish staff.
METR also inadvertently exposed a read-only SQL query mechanism through its public transcript viewer. A bug could have been exploited to reach unpublished evaluation data, and the database had accidentally been loaded with sensitive model data it was not meant to hold.
An independent researcher disclosed the flaw and METR took the interface offline and paid a bounty. It said the attackers had probed the endpoint without appearing to discover or exploit the bug.
METR said it now runs public-facing applications in an environment architecturally separated from its internal infrastructure, and described its wider security measures as accurate to July 30.
Ongoing Incident Prompts JumpCloud to Reset API Keys News 6 July 2023
Ongoing Incident Prompts JumpCloud to Reset API Keys
61% of Hackers Use New Exploit Code Within 48 Hours of Attack News 25 February 2025
61% of Hackers Use New Exploit Code Within 48 Hours of Attack
UK Government Cybersecurity Advisory Board Applications Now Open News 25 May 2022
UK Government Cybersecurity Advisory Board Applications Now Open
JPMorgan’s CISO on Overcoming Surging Threats and Regulatory Hurdles in Finance Interview 20 January 2025
JPMorgan’s CISO on Overcoming Surging Threats and Regulatory Hurdles in Finance
Five Continents, Five Voices: Siddhesh Patel, Americas Interview 3 December 2019
Five Continents, Five Voices: Siddhesh Patel, Americas
What’s Hot on Infosecurity Magazine?
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Cybersecurity Job Ads Requiring AI Skills Double
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
Fake Recruiter Scams Target Corporate Credentials on Mobile
NIST Warns of Unique Security Risks in Multi-Cloud Environments
US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate
NIST Warns of Unique Security Risks in Multi-Cloud Environments
New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims
Manchester Airports Group Hit by Cyber Incident
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
DDoS Attack Hits Norwegian Government Services
Understand How AI Systems Can Be Attacked, and Defend Them
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How To Enhance Security Operations with AI-Powered Defenses
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Securing M365 Data and Identity Systems Against Modern Adversaries
Revisiting CIA: Developing Your Security Strategy in the SaaS Shared Reality
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
