CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5873

As cited

Copy frozen at (site build).

vulnerabilities

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

METR, a model evaluation organization, disclosed two attacks from March and May 2026 in which an attacker stole an application programming interface (API) key and consumed $600,000 worth of free model credits undetected over three weeks, while a second campaign in May involved probing of public infrastructure and discovery of an inadvertently exposed database with sensitive model data. The March incident exploited a fail-open authentication bug on a personal instance, and in May attackers used agents for automated vulnerability scanning and credential attacks, though no evidence emerged that they accessed non-public information. METR has since implemented isolated production environments, hired security staff, and improved monitoring protocols.

Why it matters: Security teams managing artificial intelligence (AI) infrastructure must audit personal development instances and API key exposure, enforce spending limits on credentials, and establish usage baselines to detect anomalies, since METR's legitimate high token consumption masked the $600K theft for weeks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

METR, a model evaluation organization, disclosed two attacks from March and May 2026 in which an attacker stole an application programming interface (API) key and consumed $600,000 worth of free model credits undetected over three weeks, while a second campaign in May involved probing of public infrastructure and discovery of an inadvertently exposed database with sensitive model data. The March incident exploited a fail-open authentication bug on a personal instance, and in May attackers used agents for automated vulnerability scanning and credential attacks, though no evidence emerged that they accessed non-public information. METR has since implemented isolated production environments, hired security staff, and improved monitoring protocols.

Why it matters: Security teams managing artificial intelligence (AI) infrastructure must audit personal development instances and API key exposure, enforce spending limits on credentials, and establish usage baselines to detect anomalies, since METR's legitimate high token consumption masked the $600K theft for weeks.

VendorsAmazon Web ServicesGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary