Skip to content
Attackers Steal METR API Key and Burn $600,000 in AI Credits

Attackers Steal METR API Key and Burn $600,000 in AI Credits

Infosecurity-Magazine September 1, 2026

Attackers have stolen an API key from AI safety research organization METR and used it for three weeks to consume model credits that would have been worth $600,000.

METR disclosed the incident in a security update published on Aug 31, alongside highlighting a separate attack in May in which threat actors probed its public infrastructure. It said it had found no evidence that sensitive information was accessed in either incident.

The credits had been supplied free of charge by the unnamed model developer, so the $600,000 represents their commercial value rather than a direct financial loss.

METR said the disclosure concerned external attackers rather than AI agents acting inside its evaluations, where an initial scan had found no evidence of agents hacking third parties.

Vibe-Coded App Exposed API Key

The incident began in March when a METR researcher ran agents on a personal Amazon EC2 instance made publicly accessible behind Google authentication. The vibe-coded app held an API key for METR's public models account.

A fail-open flaw silently disabled authentication, leaving the system exposed for several days. METR said it suspected the attacker had found the instance by mining certificate transparency lists for recently registered sites carrying high-signal terms relating to language models and agents.

The attacker prompted an agent to reveal the model provider API key and added an SSH key for persistence, then used the stolen credentials to consume large volumes of model credits over three weeks.

METR said the illicit usage was hard to distinguish from legitimate evaluation activity, since its researchers routinely generated high volumes of model traffic, and it had no way to cap spending on free-credit keys.

The organization revoked the researcher's access, rotated credentials, wiped the laptop and alerted the model developer. It later added spend alerts to keys where possible.

Second Attack Probed Public Infrastructure

METR said it had been tipped off in early May that it was being targeted by attackers who appeared financially motivated and may have been seeking frontier model access.

The attackers made heavy use of agents to automate vulnerability discovery, including credential stuffing, OAuth token grant attempts, scanning of new services and attempts to phish staff.

METR also inadvertently exposed a read-only SQL query mechanism through its public transcript viewer. A bug could have been exploited to reach unpublished evaluation data, and the database had accidentally been loaded with sensitive model data it was not meant to hold.

An independent researcher disclosed the flaw and METR took the interface offline and paid a bounty. It said the attackers had probed the endpoint without appearing to discover or exploit the bug.

METR said it now runs public-facing applications in an environment architecturally separated from its internal infrastructure, and described its wider security measures as accurate to July 30.

Ongoing Incident Prompts JumpCloud to Reset API Keys News 6 July 2023

Ongoing Incident Prompts JumpCloud to Reset API Keys

61% of Hackers Use New Exploit Code Within 48 Hours of Attack News 25 February 2025

61% of Hackers Use New Exploit Code Within 48 Hours of Attack

UK Government Cybersecurity Advisory Board Applications Now Open News 25 May 2022

UK Government Cybersecurity Advisory Board Applications Now Open

JPMorgan’s CISO on Overcoming Surging Threats and Regulatory Hurdles in Finance Interview 20 January 2025

JPMorgan’s CISO on Overcoming Surging Threats and Regulatory Hurdles in Finance

Five Continents, Five Voices: Siddhesh Patel, Americas Interview 3 December 2019

Five Continents, Five Voices: Siddhesh Patel, Americas

What’s Hot on Infosecurity Magazine?

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Cybersecurity Job Ads Requiring AI Skills Double

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

Fake Recruiter Scams Target Corporate Credentials on Mobile

NIST Warns of Unique Security Risks in Multi-Cloud Environments

US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate

NIST Warns of Unique Security Risks in Multi-Cloud Environments

New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

Manchester Airports Group Hit by Cyber Incident

Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

DDoS Attack Hits Norwegian Government Services

Understand How AI Systems Can Be Attacked, and Defend Them

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How To Enhance Security Operations with AI-Powered Defenses

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

Securing M365 Data and Identity Systems Against Modern Adversaries

Revisiting CIA: Developing Your Security Strategy in the SaaS Shared Reality

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust