METR Discloses Security Incidents as Agent Bug Leaks API Key, Costing $600K

AI evaluation organization METR disclosed two security incidents from this year. In one, an agent running on a personal EC2 instance suffered a fail-open issue due to a Dashboard code bug, with Google authentication silently disabled—attackers exploited this to prompt the agent into handing over API keys, causing roughly $600,000 in total losses and highlighting how vulnerable AI agents themselves are from a security standpoint.

Confirmed

Why it matters

2026-09-01 ~ 2026-09-02 · 5 related posts

Primary sources

1 near-duplicate retellings: rohanpaul_ai