METR discloses security incidents, including a vibe-coded app with silent auth bypass
nptacek · x · 2026-09-01
AI evaluation org METR published a security update detailing two incidents earlier this year: in March, attackers stole an API key for public-model inference and burned substantial credits; in May, attackers systematically probed its public infrastructure, including an unsuccessful attempt to reach internal data via an inadvertently exposed endpoint. METR clarifies these were external attacks, not AI agents hacking during evaluations, and says a scan found no evidence of agents hacking third parties. Security investment has since increased.
The widely shared detail: a vibe-coded app included a fail-open vulnerability that silently disabled authentication.
Related event: METR Discloses Security Incidents as Agent Bug Leaks API Key, Costing $600K(5 posts)→
More from Safety
- AI commentator calls for regulation: 'It's speculation and market capture, not philosophy' — gerardsans · 2026-09-02
- Polymarket puts just 12% odds on a US AI safety bill before 2027 — Polymarket · 2026-09-02
- Zvi: Anthropic pauses high-risk RL amid alignment incidents, CoT monitorability at risk — Don't Worry About the Vase (Zvi) · 2026-09-02
- Cybersecurity experts blast METR/Redwood report: OpenAI incident was a security failure, not rogue AI — ylecun · 2026-09-02
- Study (n=504): suspicion doesn't improve AI-text detection; fake-news accuracy drops 10.2 points — bit3py · 2026-09-02
- Nvidia CEO Jensen Huang urges G20 to avoid AI regulation based on 'theoretical harms' — Polymarket · 2026-09-02