Urgent.News

What's breaking now, across thousands of outlets.

AI

METR attackers drain $600,000 in AI credits

Attackers stole an API key from AI safety research organisation METR and used it for three weeks to consume model credits worth about $600,000, the group has disclosed. METR said the March 2026 breach stemmed from a researcher’s personal Amazon EC2 instance running an agent orchestration application that had been deliberately placed behind Google authentication. A fail-open flaw in the…

Attackers stole an API key from AI safety research organization METR, and used it for three weeks to consume model credits valued at approximately $600,000. The breach occurred in March 2026 after a researcher's personal Amazon EC2 instance, running an agent orchestration application, was left exposed on the public internet. A flaw in the application's fail-open configuration inadvertently disabled authentication, rendering the system vulnerable.

The compromised instance contained an API key associated with METR's general-access account for publicly available AI models. Once the attackers discovered the exposed service, they prompted an agent to reveal the model provider's API key, added an SSH key for persistent access, and used the stolen credentials for roughly three weeks.

METR, a non-profit organization, found no compromise beyond the single stolen API key. The illicit activity went undetected due to METR's routine evaluations and experiments generating high token volumes, and the internal usage dashboard failing to display rate-limited requests. The organization revoked the researcher's access, revoked the EC2 instance, rotated credentials, and wiped the researcher's laptop.

METR alerted the partner AI company whose models were involved, and conducted forensic work to determine the scope of the incident. The disclosure also detailed a separate security incident in May, where attackers probed METR's publicly accessible infrastructure, potentially motivated by financial gain.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in AI

Anthropic broadens Claude access with Fable 5.1

Anthropic has made Claude Fable 5.1 generally available while restricting the closely related Claude Mythos 5.1 to vetted partners, pairing stronger coding and research capabilities with new safeguards for cybersecurity, biology and enterprise data.

More from Thursday 3 September →