2 Sources
[1]
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000. METR (short for Model Evaluation and Threat Research) found no evidence that
[2]
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external
Share
Copy Link
AI model testing organization METR revealed two major security breaches from 2026. In March, attackers exploited a fail-open bug to steal an API key and consumed $600,000 worth of AI credits over three weeks. In May, a sustained attack campaign targeted METR's infrastructure, though no sensitive data was accessed.

METR (Model Evaluation and Threat Research), an AI model testing organization that evaluates frontier AI models for long-horizon agentic tasks, disclosed two security incidents from early 2026
1
2
. In March 2026, attackers stole a METR API key for inference on public models and consumed AI credits worth approximately $600,000 over three weeks without detection1
. The research nonprofit found no evidence that sensitive information, including model data, credentials, or details about model architectures and release dates, was accessed in either incident2
.The March incident began when a METR researcher without access to sensitive information used agents running on a personal EC2 instance that was intentionally made publicly accessible behind Google authentication
1
. This instance contained an API key for METR's public models account. However, a "vibe-coded app" included a fail-open bug that silently disabled authentication, exposing the agent orchestration dashboard to the public internet for several days2
. METR suspects the attacker discovered the instance by scanning recently-registered websites in certificate transparency lists, searching for sites with keywords related to LLMs or agents to harvest potentially exposed model provider API keys1
.Once the attacker identified the vulnerable system, they prompted an agent directly to reveal its model provider API key, added an SSH key to maintain persistent access, and spent the next three weeks using the stolen credentials to consume API credits on public models
2
. The credits, which would have cost approximately $600,000, had been provided to METR for free by an unnamed model developer1
. METR explained why the large illicit usage went undetected: the organization regularly runs evaluations that consume high volumes of tokens, making researchers "very acclimated to getting lots of weird rate limit and API errors"1
. Additionally, since the tokens were free, METR didn't receive a large bill, and at the time there were no spending limits available for keys like the one that was stolen1
.In May 2026, METR became the target of a sustained attack campaign by what appeared to be financially motivated actors attempting to gain illicit access to frontier AI models
1
2
. After being tipped off, METR observed attackers systematically probing its publicly accessible infrastructure with heavy use of agents to automate vulnerability discovery2
. The tactics included credential stuffing against authentication providers, attempting OAuth token grants, scanning newly deployed services, and phishing attempts1
.Related Stories
During the May incident, METR unintentionally exposed a read-only SQL query mechanism via its public transcript viewer
1
. While queries were scoped to public data by default, a bug in the component allowed access to unpublished evaluation data2
. The database also accidentally included sensitive model data that should not have been present2
. An independent bug hunter discovered the vulnerability and reported it to METR, which paid a bounty and immediately took the API offline1
. Evidence shows the attackers probed this endpoint but found no indication they discovered the exploit or accessed any non-public data2
.In response to these security incidents, METR has implemented several measures to strengthen its defenses
1
. The organization now uses an isolated production environment for public-facing applications that is separate from its internal infrastructure1
. METR has also improved its security infrastructure, protocols, and review process, updated policies around placing METR credentials or data on non-METR infrastructure or devices, enhanced monitoring capabilities, and added spend alerts to keys where possible2
. The nonprofit has hired a security lead and plans to expand its security team1
. These incidents highlight the growing risks facing AI research organizations as attackers increasingly use automated agents to discover vulnerabilities and target valuable AI resources.Summarized by
Navi
[1]
13 Aug 2026•Technology

29 May 2026•Technology

17 Sept 2026•Technology

1
Technology

2
Science and Research

3
Technology
