[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAv3qKrV14rcCwnyMtZc1pOH04nGwCUSQUfLasboabYE":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"b739229a-ce6a-4b09-b151-5aabd691a98e","Attackers Steal METR API Key and Consume AI Credits Worth About $600,000","attackers-steal-metr-api-key-and-consume-ai-credits-worth-about-600-000-651b2a","METR (short for Model Evaluation and Threat Research and pronounced \"Meter\"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered \"two notable security incidents\" where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to","METR, a non-profit researching AI models, disclosed two security incidents. In March 2026, attackers stole an API key from a researcher's exposed instance, consuming approximately $600,000 worth of AI credits over three weeks. In May 2026, a sustained attack campaign probed METR's infrastructure, including an attempt to access internal data via an exposed SQL endpoint. No sensitive information is believed to have been compromised.","METR reports API key theft and $600k AI credit consumption by attackers.","Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 Ravie LakshmananSep 01, 2026Cyber Attack \u002F Artificial Intelligence METR (short for Model Evaluation and Threat Research and pronounced \"Meter\"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered \"two notable security incidents\" where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to have been accessed as a result of these incidents, it said, adding that a version of its findings was shared with AI companies it works with prior to public disclosure. The attacks have not been attributed to any known threat actor or group, nor did they involve AI agents breaking into its evaluations. \"In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,\" METR said. \"In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.\" The March Incident According to METR, one of its researchers with no sensitive access is said to have used agents running on a personal EC2 instance that was intentionally made publicly accessible behind Google authentication. The instance contained an API key for METR's general-access (public models) account. However, the \"vibe-coded app\" suffered from a \"fail-open vulnerability\" that silently disabled authentication, causing the agent orchestration dashboard to be exposed to the public internet for several days. \"From our analysis, we suspect that the attacker found the instance by looking through recently-registered websites (e.g., in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,\" METR explained. Once the system was identified, the threat actor prompted an agent directly to reveal its model provider API key, added an SSH key for persistent access, and used the stolen credentials to consume a significant amount of API credits on publicly-available models over a period of three weeks. METR said the accrued credits would have racked up approximately $600,000 in bills had it not been provided to the non-profit for free by the model provider. It did not name the AI company. It also noted that the illicit usage was not immediately caught because it runs large-scale evaluations and experiments that typically consume a high volume of tokens and the fact that there were no caps on token spend. Following the incident, METR said it has updated its security policies around putting METR credentials or data on non-METR infrastructure or devices, improved monitoring, and added spend alerts to keys where possible. The May Incident The second attack observed in May 2026 has been described as a \"sustained external attack campaign\" orchestrated by a likely financially motivated threat actor to obtain unlawful access to frontier AI models. \"We observed the attackers systematically probing our publicly accessible infrastructure, with heavy use of agents to automate vulnerability discovery, including by credential stuffing authentication providers, attempting OAuth token grants, scanning newly deployed services, and attempting to phish staff,\" METR said. Around the same time, the research entity said it inadvertently exposed a read-only SQL query mechanism built into its public transcript viewer. Although the queries were scoped to public data by default, a bug in the component could have been exploited to access unpublished evaluation data. In addition, the database \"accidentally included\" sensitive model data, despite the fact that it was supposed to contain only data from non-sensitive models. METR said it became aware of the issue only after an independent security researcher discovered and reported it, resulting in the API being taken offline. \"The attackers had probed this endpoint in passing as part of their broader campaign, but the evidence shows no indication that they discovered the exploit or accessed any non-public data,\" METR said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Cloud security, Cyber Attack, Vulnerability, Web Security ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fattackers-steal-metr-api-key-and.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEh2b-1gQHvYc7ZLc86QFtZ2LoJ7zFalpJtSy_e_laxiM_f4Ftnhuvp5eCJZRSk2NL_0tZAZAl2z1UPYfOBSTbdGOPOZexgt3GkuUqsrZPgFB2F-qG2Ir_c7Ioj6zcJVdWjzBo90HpcObPWan5eID2df6OXyn3F7-LRpdOvO8TfiZSp8L2j89p2UbsDi3zM4\u002Fs1600\u002Fmetr.jpg","2026-09-01T09:05:30+00:00","2026-09-01T12:00:10.176888+00:00",7,[18,21,24,27,29],{"name":19,"type":20},"Google authentication","product",{"name":22,"type":23},"Google","vendor",{"name":25,"type":26},"Artificial Intelligence","technology",{"name":28,"type":26},"LLM",{"name":30,"type":26},"OAuth","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":31,"icon":33,"name":34,"slug":35},null,"Threat Intelligence","threat-intelligence",[37,42,47],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":48},{"id":31,"icon":33,"name":34,"slug":35},[50],{"type":51,"value":52,"context":53},"url","https:\u002F\u002Fgithub.com\u002Fvibe-util\u002Fvibe-util","The 'vibe-coded app' framework used by the researcher, which had a vulnerability leading to API key exposure."]