metr.org
API Key Theft at METR Costs $600,000 in AI Credits
Article Content
METR disclosed two significant security incidents involving unauthorized access attempts to its systems. In March 2026, attackers stole an API key for public models, leading to the consumption of approximately $600,000 in credits, which were provided for free by the model provider. The attackers exploited a fail-open vulnerability in a researcher’s EC2 instance that was publicly accessible. In May 2026, METR observed a sustained probing of its infrastructure, including an unsuccessful attempt to access internal data through an exposed endpoint. No sensitive information was accessed in either incident. METR has since updated its security policies, improved monitoring, and added spend alerts to its API keys. The attacks have not been attributed to any known threat actor or group.
Key Points: • Attackers stole an API key, costing METR $600,000 in AI credits. • A fail-open vulnerability allowed unauthorized access to a public EC2 instance. • METR has enhanced its security measures following the incidents.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.