HackMyIP
← Back to News
2026-09-01 The Hacker News

METR API Key Stolen, $600K in AI Credits Consumed by Attackers

AI SecurityVulnerabilityIncident Response

METR (Model Evaluation and Threat Research), a non-profit that evaluates frontier AI models for agentic task performance, disclosed two notable security incidents in which external actors attempted unauthorized access to its systems. According to METR, no sensitive information is believed to have been compromised, and a version of its findings was shared with partner AI companies prior to public disclosure. The attacks have not been attributed to any known threat actor, and notably, neither incident involved AI agents breaking into METR's evaluations directly.

In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits over three weeks. METR explained that one of its researchers had deployed agents on a personal EC2 instance intentionally made publicly accessible behind Google authentication, which contained an API key for METR's general-access public models account. However, the "vibe-coded app" suffered from a fail-open vulnerability that silently disabled authentication, exposing the agent orchestration dashboard to the public internet for several days. The attacker is suspected to have discovered the instance by scanning recently-registered websites in certificate transparency lists for high-signal keywords relating to LLMs or agents. Once identified, the threat actor prompted an agent to reveal its model provider API key, added an SSH key for persistent access, and drained API credits on publicly-available models. METR noted the accrued usage would have generated approximately $600,000 in charges had the credits not been provided to the non-profit for free by the unnamed AI provider. The illicit usage went undetected due to METR's high baseline token consumption from large-scale evaluations and the absence of spend caps. Organizations can audit their own exposure to similar risks by running a SSL/TLS checker on publicly accessible endpoints and testing authentication configurations.

A second incident in May 2026 involved a "sustained external attack campaign" in which attackers systematically probed METR's publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint. Following both incidents, METR has updated its security policies around placing METR credentials or data on non-METR infrastructure, improved monitoring capabilities, and added spend alerts to API keys where possible. The organization did not name the AI model provider whose credits were consumed or attribute the activity to any specific threat group. Security teams managing similar cloud-hosted AI workloads are advised to validate their attack surface using a port scanner and verify that exposed services enforce authentication strictly, particularly for any "vibe-coded" prototypes running on personal or unmanaged infrastructure.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →