METR Discloses Security Incidents: Attackers Stole API Key, Consumed $600K in AI Credits Undetected

2 Sources

Share

AI model testing organization METR revealed two major security breaches from 2026. In March, attackers exploited a fail-open bug to steal an API key and consumed $600,000 worth of AI credits over three weeks. In May, a sustained attack campaign targeted METR's infrastructure, though no sensitive data was accessed.

News article

Attackers Stole a METR API Key and Consumed $600K in Credits

METR (Model Evaluation and Threat Research), an AI model testing organization that evaluates frontier AI models for long-horizon agentic tasks, disclosed two security incidents from early 2026

1

2

. In March 2026, attackers stole a METR API key for inference on public models and consumed AI credits worth approximately $600,000 over three weeks without detection

1

. The research nonprofit found no evidence that sensitive information, including model data, credentials, or details about model architectures and release dates, was accessed in either incident

2

.

Fail-Open Bug Exposed Publicly Accessible EC2 Instance

The March incident began when a METR researcher without access to sensitive information used agents running on a personal EC2 instance that was intentionally made publicly accessible behind Google authentication

1

. This instance contained an API key for METR's public models account. However, a "vibe-coded app" included a fail-open bug that silently disabled authentication, exposing the agent orchestration dashboard to the public internet for several days

2

. METR suspects the attacker discovered the instance by scanning recently-registered websites in certificate transparency lists, searching for sites with keywords related to LLMs or agents to harvest potentially exposed model provider API keys

1

.

Three-Week Exploitation Period Went Unnoticed

Once the attacker identified the vulnerable system, they prompted an agent directly to reveal its model provider API key, added an SSH key to maintain persistent access, and spent the next three weeks using the stolen credentials to consume API credits on public models

2

. The credits, which would have cost approximately $600,000, had been provided to METR for free by an unnamed model developer

1

. METR explained why the large illicit usage went undetected: the organization regularly runs evaluations that consume high volumes of tokens, making researchers "very acclimated to getting lots of weird rate limit and API errors"

1

. Additionally, since the tokens were free, METR didn't receive a large bill, and at the time there were no spending limits available for keys like the one that was stolen

1

.

Sustained Attack Campaign Targeted Frontier AI Models Access

In May 2026, METR became the target of a sustained attack campaign by what appeared to be financially motivated actors attempting to gain illicit access to frontier AI models

1

2

. After being tipped off, METR observed attackers systematically probing its publicly accessible infrastructure with heavy use of agents to automate vulnerability discovery

2

. The tactics included credential stuffing against authentication providers, attempting OAuth token grants, scanning newly deployed services, and phishing attempts

1

.

Exposed Endpoint Allowed Access to Unpublished Evaluation Data

During the May incident, METR unintentionally exposed a read-only SQL query mechanism via its public transcript viewer

1

. While queries were scoped to public data by default, a bug in the component allowed access to unpublished evaluation data

2

. The database also accidentally included sensitive model data that should not have been present

2

. An independent bug hunter discovered the vulnerability and reported it to METR, which paid a bounty and immediately took the API offline

1

. Evidence shows the attackers probed this endpoint but found no indication they discovered the exploit or accessed any non-public data

2

.

METR Implements Infrastructure Isolation and Spend Alerts

In response to these security incidents, METR has implemented several measures to strengthen its defenses

1

. The organization now uses an isolated production environment for public-facing applications that is separate from its internal infrastructure

1

. METR has also improved its security infrastructure, protocols, and review process, updated policies around placing METR credentials or data on non-METR infrastructure or devices, enhanced monitoring capabilities, and added spend alerts to keys where possible

2

. The nonprofit has hired a security lead and plans to expand its security team

1

. These incidents highlight the growing risks facing AI research organizations as attackers increasingly use automated agents to discover vulnerabilities and target valuable AI resources.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved