VMTech
Discuss a project

METR reports API key theft and $600,000 in AI credit consumption

METR reports API key theft and $600,000 in AI credit consumption

Model Evaluation and Threat Research (METR), a non-profit that evaluates frontier AI models on long-horizon agentic tasks, has disclosed two security incidents involving attempted unauthorised access to its systems. In March 2026, an attacker stole an API key for inference on public models and used credits that would have generated approximately $600,000 in charges. In May, METR observed a sustained campaign probing its public infrastructure.

METR said it does not believe sensitive information was accessed in either incident. The activity has not been attributed to a known actor or group, and the organisation stressed that AI agents did not break into its evaluations. It shared a version of its findings with the AI companies it works with before making the disclosure public.

A fail-open app exposed a public-model credential

The March incident began with a researcher who did not have sensitive access. The researcher used agents on a personal Amazon EC2 instance deliberately made publicly reachable behind Google authentication. That instance contained an API key for METR's general-access account, used for publicly available models.

METR said a “vibe-coded” application on the instance contained a fail-open vulnerability that silently disabled authentication. The agent orchestration dashboard was therefore exposed to the public internet for several days. Its analysis suggests the attacker may have searched recently registered websites, including certificate transparency lists, for sites with LLM- or agent-related keywords in an effort to harvest exposed model-provider credentials.

After locating the system, the attacker prompted an agent directly to disclose its model-provider API key, added an SSH key for persistent access, and consumed API credits over three weeks. The model provider had supplied the credits to METR free of charge, and METR did not identify that company. The unauthorised consumption was not detected immediately because METR's large evaluations normally use high token volumes and the key had no token-spend cap.

Separate campaign probed public services

In May, METR detected what it described as a likely financially motivated campaign seeking unlawful access to frontier AI models. The actors systematically probed publicly accessible services, using agents heavily to automate vulnerability discovery. METR observed credential stuffing against authentication providers, attempted OAuth token grants, scans of newly deployed services, and efforts to phish staff.

During that period, METR also inadvertently exposed a read-only SQL query mechanism in its public transcript viewer. Although queries were scoped to public data by default, a component bug could have allowed access to unpublished evaluation data. The database also accidentally contained sensitive model data even though it was intended to hold data from non-sensitive models.

An independent security researcher reported the SQL issue, after which METR took the API offline. METR said the attackers had probed the endpoint as part of their wider activity, but available evidence does not indicate that they found the exploit or accessed non-public information.

Controls must cover usage as well as access

METR has revised its policies for placing its credentials or data on non-METR infrastructure and devices, improved monitoring, and added spend alerts to keys where possible. For organisations operating AI workloads, the incident underlines the practical need to keep credentials off unmanaged systems and pair access controls with usage monitoring and spend limits.

#aigovernance#apikeysecurity#cloudsecurity#credentialsecurity
Open analytics
On the site 1 views
min read 4 01.09.2026
Instagram

METR reports API key theft and $600,000 in AI credit consumption

Open the post on Instagram ↗