METR API key theft burns $600K in free AI credits

Attackers exploited a misconfigured agent dashboard at AI safety nonprofit METR earlier this year, stealing an API key tied to public inference models and running up roughly $600,000 worth of compute credits over three weeks before the abuse was detected and cut off.[1][3][5][11]

METR, short for Model Evaluation and Threat Research, disclosed in a security update that the incident was one of two notable attacks against its infrastructure in 2026, emphasizing that the stolen key only granted access to public models and that no sensitive evaluation data or internal systems were compromised.[3][10][11]

According to METR’s account and subsequent reporting, the chain of events began when a researcher deployed an experimental, “vibe-coded” agent application on a personal Amazon EC2 instance that was intentionally exposed to the internet but gated behind Google authentication.[1][3][5] A fail-open bug in that authentication flow left an agent dashboard reachable without proper login, giving the attacker a foothold.[5][6] From there, the intruder prompted an agent to reveal the model provider’s API key, added an SSH key for persistence on the EC2 instance, and used the stolen credential for around three weeks to drive large volumes of inference requests on publicly available models.[1][3][6][10]

The compute usage would have translated into approximately $600,000 in charges if METR had been paying retail rates, but the credits were supplied free of charge by an unnamed model vendor, sparing the nonprofit from a direct financial hit.[1][3][5] METR’s forensic review concluded that the compromise was confined to the public-model account associated with that key, and there was no evidence of access to internal evaluation environments or other sensitive systems.[3][10][11] No CVE identifiers, vendor advisories or government alerts have been issued in connection with the episode, underscoring that it stemmed from credential exposure and access control weaknesses rather than a flaw in a commercial software product.[1][3][11]

In a follow-up, METR said it also observed a separate campaign in which external actors systematically probed its publicly accessible infrastructure, but those attempts did not result in theft of additional credentials or access to internal data.[10][11] The organization framed both incidents as warning signs about the operational risks that come with running complex agent-based systems on cloud infrastructure, particularly when experiments spill over from tightly controlled corporate environments onto personal or lightly managed machines.[3][10][11]

METR responded by tightening policies around the use of organizational credentials on non-METR devices or infrastructure, increasing monitoring of API usage, and adding spend alerts and caps wherever possible to detect anomalous consumption patterns quickly.[1][3][11] The nonprofit’s broader guidance—echoing its earlier recommendations to NIST on AI misuse risk—stresses enforcing strong, random keys, hardening authentication flows, and treating agent dashboards and orchestration layers as high-value assets that warrant the same protection as traditional administrative consoles.[11][15]

References

  1. Attackers Steal METR API Key and Consume AI Credits …
  2. A vibe-coded app exposed METR’s API key and consumed $600,000 in free credits
  3. METR-Angriff: API-Schlüssel gestohlen und KI-Credits im Wert von ca. 600.000 US-Dollar verbrannt
  4. Attackers stole a METR API key and used it for three weeks …
  5. SignalSec | Cyber Intelligence
  6. METR
  7. METR – Comment on NIST AI 800-1 (Managing Misuse Risk for Dual-Use Foundation Models)

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply