AI Model Evaluator METR Suffers Credential Theft, API Key Compromise
Security nonprofit METR disclosed two cybersecurity incidents, including a breach where an API key was stolen and used to rack up $600,000 in AI model credits.

The nonprofit organization METR (Model Evaluation and Threat Research), which plays a crucial role in assessing the risks of advanced AI models, has revealed two significant cybersecurity incidents that occurred earlier this year. The first, in March, involved the theft of an API key used for accessing public AI models, leading to substantial consumption of cloud credits. The second, in May, saw attackers probing METR's publicly accessible infrastructure, including an unsuccessful attempt to access sensitive internal data through an inadvertently exposed endpoint.
While METR characterized both events as "near misses," the March incident resulted in a successful compromise. Threat actors managed to steal an API key and use it to gain persistence on a system for several weeks. This stolen key was then exploited to consume approximately $600,000 worth of credits for inference on publicly available AI models. METR suspects the attackers found the compromised system by scanning recently registered "vibe-coded" websites, which are often used for AI model development and can inadvertently expose API keys.
METR's data is categorized into four tiers, ranging from publicly available information to highly sensitive intellectual property and business data. The March breach specifically involved an AWS EC2 instance that was inadvertently exposed to the internet due to a "fail-open vulnerability" in an AI agent orchestration tool. This allowed the attacker to extract the API key for METR's public models account, add an SSH key for persistence, and operate undetected for three weeks.
In response to the March incident, METR took immediate action by revoking the compromised access, rotating credentials, and conducting forensic analysis. The organization also enhanced its security posture by strengthening deployment policies for employees, particularly concerning the use of METR credentials on non-METR infrastructure, and improving monitoring and alerting for unusual API key usage.
The May incident involved a more sustained external attack campaign where threat actors used automated agents for reconnaissance and vulnerability discovery. This included credential stuffing, OAuth-related attacks, scanning for new services, and phishing attempts. During this period, METR inadvertently exposed a read-only SQL query mechanism via its public transcript viewer, which, if chained with another vulnerability, could have potentially exposed unpublished evaluation data, primarily Category 2 and some Category 3 data.
METR stated that there is no evidence that attackers discovered this specific exploit or accessed any non-public data during the May campaign. However, in response, the organization temporarily shut down public-facing services, improved network segmentation between public and internal systems, and commissioned additional security testing. METR also increased its overall security investments, including hiring a dedicated security lead, shutting down legacy infrastructure, conducting regular threat modeling, and enhancing logging and monitoring.
These incidents highlight the growing security challenges within the AI ecosystem. METR, known for its collaborations with major AI vendors like OpenAI, Anthropic, Google, Meta, and Amazon, holds a significant position in AI security. The compromise of its systems underscores the risks associated with API key management, the security of AI development tools, and the potential for sophisticated attacks targeting organizations at the forefront of AI evaluation.
METR has emphasized that it has no evidence of its agents hacking third parties during evaluations or of its own evaluations being compromised by external agents. The incidents serve as a stark reminder for organizations, especially those handling sensitive AI data and infrastructure, to continuously review and strengthen their security practices.