Attackers stole METR API keys and burned ~$600K in credits over three weeks

METR, a nonprofit that evaluates frontier AI models, has disclosed a security incident: in March 2026, a researcher's public agent dashboard left Google authentication silently disabled for several days due to a fail-open flaw, exposing it to the public internet. An attacker used prompt injection to trick the agent into handing over its API key and planted an SSH persistence backdoor, burning roughly $600,000 in credits over about three weeks. The incident was first reported by @beffjezos and covered by security outlet The Hackers News, with multiple accounts resharing consistent information.

Confirmed

Why it matters

2026-09-14 ~ 2026-09-14 · 5 related posts

Primary sources