Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
The model provider gave METR the credits for free. An actual customer would not have been so lucky
Two attacks on AI model testing organization METR were revealed earlier this year, including one where an attacker stole an API key and spent three weeks consuming approximately $600,000 worth of public-model credits. METR, which stands for Model Evaluation and Threat Research, discovered no evidence of sensitive information being accessed in either incident. Both attacks were investigated alongside security experts.
On March 2026, a METR researcher unintentionally left a personal EC2 instance publicly accessible behind Google authentication. This instance contained an API key for METR's public models account, which an attacker discovered using a vibe-coded app. The app included a fail-open bug that disabled authentication, exposing the system to the public internet for several days.
The attacker then used an SSH key to maintain persistent access and consumed the stolen API credits over the next three weeks, amounting to about $600,000. Fortunately, the free credits were provided by a model developer to METR.
In May 2026, METR experienced a second attack campaign, during which researchers noticed attackers probing their publicly accessible infrastructure. The intruders attempted to gain initial access using various methods, such as automated vulnerability discovery, credential stuffing, OAuth token grants, service scanning, and phishing attempts.
Additionally, METR inadvertently exposed a read-only SQL query mechanism via its public transcript viewer, which could access unpublished evaluation data. However, no sensitive model data was accessed, according to METR. An independent bug hunter discovered the vulnerability and reported it to METR, who paid the researcher a bounty and took the API offline.
In response to both incidents, METR has implemented improved security infrastructure, protocols, review processes, and has hired a security lead, with plans to add more security staff.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.