ZeroHour
Infosecurity Magazinepublished ()ingested

Attackers Steal METR API Key and Burn $600,000 in AI Credits

mediumAI safety & security exploited in the wildimportance 45
AI summary · glm-5.3-flash

Attackers used a stolen METR API key for three weeks, burning $600,000 in AI model credits before the abuse was stopped.

Attackers obtained a METR API key and used it without authorization for roughly three weeks, consuming AI model credits worth $600,000. The incident, reported by Infosecurity Magazine, shows how stolen cloud AI credentials can drive rapid, high-cost abuse. It underscores the need for API key hygiene, usage monitoring, and spend alerts on AI accounts.

  • Unauthorized API use lasted approximately three weeks.
  • Estimated loss of $600,000 in AI credits.
  • Highlights detection gaps around anomalous AI API consumption.
VendorsMETR
VictimsMETR
OrganizationsMETR
Full article

Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000

This source does not provide full text. Read it at infosecurity-magazine.com.