{
  "id": 4953549,
  "title": "Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks",
  "url": "https://urgent.news/2026/09/01/attacker-stole-a-metr-api-key-used-600k-worth-of-credits-and-no-one",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-01T20:45:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/01/attacker-stole-a-metr-api-key-used-600k-worth-of-credits-and-no-one-noticed-for-weeks/5293730"
  },
  "original_language": "en",
  "account": "Two attacks on AI model testing organization METR were revealed earlier this year, including one where an attacker stole an API key and spent three weeks consuming approximately $600,000 worth of public-model credits. METR, which stands for Model Evaluation and Threat Research, discovered no evidence of sensitive information being accessed in either incident. Both attacks were investigated alongside security experts.\n\nOn March 2026, a METR researcher unintentionally left a personal EC2 instance publicly accessible behind Google authentication. This instance contained an API key for METR's public models account, which an attacker discovered using a vibe-coded app. The app included a fail-open bug that disabled authentication, exposing the system to the public internet for several days. The attacker then used an SSH key to maintain persistent access and consumed the stolen API credits over the next three weeks, amounting to about $600,000. Fortunately, the free credits were provided by a model developer to METR.\n\nIn May 2026, METR experienced a second attack campaign, during which researchers noticed attackers probing their publicly accessible infrastructure. The intruders attempted to gain initial access using various methods, such as automated vulnerability discovery, credential stuffing, OAuth token grants, service scanning, and phishing attempts. Additionally, METR inadvertently exposed a read-only SQL query mechanism via its public transcript viewer, which could access unpublished evaluation data. However, no sensitive model data was accessed, according to METR. An independent bug hunter discovered the vulnerability and reported it to METR, who paid the researcher a bounty and took the API offline. In response to both incidents, METR has implemented improved security infrastructure, protocols, review processes, and has hired a security lead, with plans to add more security staff.",
  "summary": "The model provider gave METR the credits for free. An actual customer would not have been so lucky",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks",
        "url": "https://urgent.news/2026/09/01/attacker-stole-a-metr-api-key-used-600k-worth-of-credits-and-no-one-4957265",
        "published": "2026-09-01T20:45:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}