Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
The model provider gave METR the credits for free. An actual customer would not have been so lucky
Model Evaluation and Threat Research (METR) organization disclosed two security incidents that occurred earlier this year, involving an attacker who stole an API key and consumed approximately $600,000 worth of credits. In the first incident, occurring in March 2026, a METR researcher inadvertently left an EC2 instance publicly accessible, exposing an API key for the organization's public models account.
An attacker discovered this instance by searching certificate transparency lists for websites with high-signal keywords related to LLMs or agents. The attacker then used the stolen API key to consume credits on public models for three weeks, but the model developer had provided the credits for free. In the second incident in May 2026, METR was targeted by a sustained external attack campaign.
The attackers attempted to gain illicit access to frontier models by probing infrastructure, attempting credential stuffing, and scanning newly deployed services. Additionally, an unintentional exposure of a read-only SQL query mechanism via the public transcript viewer allowed potentially sensitive model data to be accidentally included in the database.
However, there is no evidence that the attacker accessed any non-public data. METR has since taken steps to improve its security, including hiring a security lead, adding more security staff, and creating an isolated production environment for public-facing applications.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.