Back to all lessons
Awareness Lessons
last month

Exposed API Key Costs AI Non-Profit $600K in Stolen Credits

METR suffered a costly breach when an API key was left exposed on a researcher's publicly accessible instance, allowing attackers to silently consume $600,000 worth of AI credits over three weeks before detection. The root problem was a combination of poor secret management and insufficient monitoring — credentials were stored or exposed in an insecure manner, and no alerting existed to flag abnormal API usage at scale. A secondary incident revealed an exposed SQL endpoint, indicating systemic gaps in how internet-facing services are inventoried and hardened. These incidents matter because even non-financial organizations can suffer massive indirect financial losses through credential abuse, and exposed database endpoints represent a critical risk of data exfiltration.

Tactical Insight

Immediate actions

  • Rotate and revoke all API keys and secrets that may have been exposed in publicly accessible environments immediately.
  • Audit all internet-facing instances and endpoints to identify and close unauthorized or unintended exposure, including SQL interfaces.

Detection & Monitoring

  • Configure real-time spend and usage alerts on all AI/cloud API accounts to trigger notifications when consumption exceeds defined thresholds.
  • Implement centralized logging for all API key usage with anomaly detection to flag unusual access patterns or geographic anomalies.

Long-term improvements

  • Enforce secrets management tooling (e.g., HashiCorp Vault, AWS Secrets Manager) so API keys are never stored in code, config files, or accessible instances.
  • Adopt a zero-trust posture for researcher environments by restricting outbound API calls to approved destinations via allowlists.
  • Conduct regular automated scans of all infrastructure to detect exposed services, open ports, and misconfigured endpoints before attackers find them.