VYPR
breachPublished Sep 1, 2026· 1 source

Attackers Steal METR API Key, Consume $600K in AI Credits

METR, a non-profit focused on AI model evaluation, disclosed two security incidents where attackers stole an API key and attempted unauthorized access, leading to the consumption of approximately $600,000 in AI credits.

METR (Model Evaluation and Threat Research), a research non-profit dedicated to evaluating advanced AI models, has revealed it was the target of two significant security incidents. In the first incident, attackers successfully stole an API key, leading to the unauthorized consumption of AI credits valued at around $600,000. While the attackers attempted to gain unauthorized access in both events, METR stated that no sensitive information is believed to have been compromised.

The first incident occurred in March 2026 when an API key for accessing public AI models was compromised. The key was inadvertently exposed on a researcher's personal EC2 instance, which was intentionally made publicly accessible but suffered from a "fail-open vulnerability" that disabled authentication. Attackers are suspected to have found the instance by searching for websites with keywords related to LLMs or agents. Once identified, the threat actor prompted an agent to reveal the API key, added an SSH key for persistence, and proceeded to consume a substantial amount of AI credits over three weeks.

METR noted that the illicit usage went undetected initially because its large-scale evaluations naturally consume a high volume of tokens, and there were no spending caps on the compromised key. The non-profit has since updated its security policies regarding the use of METR credentials on non-METR infrastructure, enhanced monitoring, and implemented spend alerts for API keys where feasible. The AI model provider, which was not named, provided the credits free of charge.

The second incident, observed in May 2026, involved a "sustained external attack campaign" by a likely financially motivated actor. Attackers systematically probed METR's publicly accessible infrastructure, employing agents to automate vulnerability discovery. This included attempts at credential stuffing, exploiting OAuth token grants, scanning new services, and phishing staff.

During this period, METR also inadvertently exposed a read-only SQL query mechanism within its public transcript viewer. Although designed to query only public data, a bug could have potentially allowed access to unpublished evaluation data. The database also contained sensitive model data, contrary to its intended scope. This vulnerability was discovered and reported by an independent security researcher, leading to the API being taken offline.

METR confirmed that while attackers had probed this specific endpoint as part of their broader campaign, there is no evidence they discovered the exploit or accessed any non-public data. The organization shared a version of its findings with AI companies it collaborates with before making the details public. The attacks have not been attributed to any known threat actor, nor did they involve AI agents breaking into METR's evaluations.

These incidents highlight the evolving threat landscape surrounding AI development and deployment. As organizations increasingly rely on AI models and cloud-based inference services, securing API keys and infrastructure becomes paramount. The financial implications, as demonstrated by the $600,000 in consumed credits, underscore the need for robust security practices, including access control, monitoring, and spending limits, particularly when dealing with powerful AI resources.

Synthesized by Vypr AI