API Key Theft at METR Costs $600,000 in AI Credits

API Key Theft at METR Costs $600,000 in AI Credits

First seen 1 Sep 2026, 09:59 UTC Thehackernewsmetr.orgowasp.org 54.1

Article Content

Browse articles
ThreatCluster

METR disclosed two significant security incidents involving unauthorized access attempts to its systems. In March 2026, attackers stole an API key for public models, leading to the consumption of approximately $600,000 in credits, which were provided for free by the model provider. The attackers exploited a fail-open vulnerability in a researcher’s EC2 instance that was publicly accessible. In May 2026, METR observed a sustained probing of its infrastructure, including an unsuccessful attempt to access internal data through an exposed endpoint. No sensitive information was accessed in either incident. METR has since updated its security policies, improved monitoring, and added spend alerts to its API keys. The attacks have not been attributed to any known threat actor or group.

Key Points: • Attackers stole an API key, costing METR $600,000 in AI credits. • A fail-open vulnerability allowed unauthorized access to a public EC2 instance. • METR has enhanced its security measures following the incidents.

Timeline

2026-03-01
API key stolen
Attackers stole an API key for public models, consuming credits worth $600,000.
Thehackernews
2026-05-01
Probing of METR infrastructure
Attackers conducted a sustained probing of METR's infrastructure, attempting to access internal data.
Thehackernews
2026-09-01
Security update published
METR published a security update detailing the incidents and their responses.
metr.org