{
  "id": 5273885,
  "title": "METR attackers drain $600,000 in AI credits",
  "url": "https://urgent.news/2026/09/03/metr-attackers-drain-600-000-in-ai-credits",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-03T05:40:43.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/metr-attackers-drain-600000-in-ai-credits/"
  },
  "original_language": "en",
  "account": "Attackers stole an API key from AI safety research organization METR, and used it for three weeks to consume model credits valued at approximately $600,000. The breach occurred in March 2026 after a researcher's personal Amazon EC2 instance, running an agent orchestration application, was left exposed on the public internet. A flaw in the application's fail-open configuration inadvertently disabled authentication, rendering the system vulnerable. The compromised instance contained an API key associated with METR's general-access account for publicly available AI models. Once the attackers discovered the exposed service, they prompted an agent to reveal the model provider's API key, added an SSH key for persistent access, and used the stolen credentials for roughly three weeks. METR, a non-profit organization, found no compromise beyond the single stolen API key. The illicit activity went undetected due to METR's routine evaluations and experiments generating high token volumes, and the internal usage dashboard failing to display rate-limited requests. The organization revoked the researcher's access, revoked the EC2 instance, rotated credentials, and wiped the researcher's laptop. METR alerted the partner AI company whose models were involved, and conducted forensic work to determine the scope of the incident. The disclosure also detailed a separate security incident in May, where attackers probed METR's publicly accessible infrastructure, potentially motivated by financial gain.",
  "summary": "Attackers stole an API key from AI safety research organisation METR and used it for three weeks to consume model credits worth about $600,000, the group has disclosed. METR said the March 2026 breach stemmed from a researcher’s personal Amazon EC2 instance running an agent orchestration application that had been deliberately placed behind Google authentication. A fail-open flaw in the…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}