ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

mediumData breach exploited in the wildimportance 52
AI summary · glm-5.3-flash

METR disclosed attackers stole an API key and burned about $600,000 in inference credits, plus a second probing campaign against its infrastructure.

METR, the AI model evaluation non-profit, disclosed two 2026 security incidents. In March, attackers found a publicly exposed EC2 instance behind a fail-open authentication bug, prompted an agent to reveal its API key, added SSH persistence, and consumed roughly $600,000 in inference credits over three weeks. In May, a likely financially motivated actor systematically probed METR's public infrastructure using agents for vulnerability discovery, credential stuffing, OAuth token grants and staff phishing, with no confirmed access to non-public data.

  • March attackers harvested API keys from vibe-coded, publicly exposed agent dashboards
  • ~$600,000 in credits consumed undetected due to normal high token spend
  • May campaign used agents to automate credential stuffing and OAuth token abuse
  • Exposed read-only SQL mechanism in transcript viewer risked unpublished eval data
  • No sensitive information believed accessed in either incident
ProductsEC2
VictimsMETR
OrganizationsMETR
Full article663 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 01, 2026Cyber Attack / Artificial Intelligence

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its systems.

No sensitive information is believed to have been accessed as a result of these incidents, it said, adding that a version of its findings was shared with AI companies it works with prior to public disclosure. The attacks have not been attributed to any known threat actor or group, nor did they involve AI agents breaking into its evaluations.

"In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits," METR said. "In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint."

The March Incident

According to METR, one of its researchers with no sensitive access is said to have used agents running on a personal EC2 instance that was intentionally made publicly accessible behind Google authentication. The instance contained an API key for METR's general-access (public models) account.

However, the "vibe-coded app" suffered from a "fail-open vulnerability" that silently disabled authentication, causing the agent orchestration dashboard to be exposed to the public internet for several days.

"From our analysis, we suspect that the attacker found the instance by looking through recently-registered websites (e.g., in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys," METR explained.

Once the system was identified, the threat actor prompted an agent directly to reveal its model provider API key, added an SSH key for persistent access, and used the stolen credentials to consume a significant amount of API credits on publicly-available models over a period of three weeks.

METR said the accrued credits would have racked up approximately $600,000 in bills had it not been provided to the non-profit for free by the model provider. It did not name the AI company.

It also noted that the illicit usage was not immediately caught because it runs large-scale evaluations and experiments that typically consume a high volume of tokens and the fact that there were no caps on token spend. Following the incident, METR said it has updated its security policies around putting METR credentials or data on non-METR infrastructure or devices, improved monitoring, and added spend alerts to keys where possible.

The May Incident

The second attack observed in May 2026 has been described as a "sustained external attack campaign" orchestrated by a likely financially motivated threat actor to obtain unlawful access to frontier AI models.

"We observed the attackers systematically probing our publicly accessible infrastructure, with heavy use of agents to automate vulnerability discovery, including by credential stuffing authentication providers, attempting OAuth token grants, scanning newly deployed services, and attempting to phish staff," METR said.

Around the same time, the research entity said it inadvertently exposed a read-only SQL query mechanism built into its public transcript viewer. Although the queries were scoped to public data by default, a bug in the component could have been exploited to access unpublished evaluation data.

In addition, the database "accidentally included" sensitive model data, despite the fact that it was supposed to contain only data from non-sensitive models. METR said it became aware of the issue only after an independent security researcher discovered and reported it, resulting in the API being taken offline.

"The attackers had probed this endpoint in passing as part of their broader campaign, but the evidence shows no indication that they discovered the exploit or accessed any non-public data," METR said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html