METR discloses security incidents, including a vibe-coded app with silent auth bypass

nptacek · x · 2026-09-01

AI evaluation org METR published a security update detailing two incidents earlier this year: in March, attackers stole an API key for public-model inference and burned substantial credits; in May, attackers systematically probed its public infrastructure, including an unsuccessful attempt to reach internal data via an inadvertently exposed endpoint. METR clarifies these were external attacks, not AI agents hacking during evaluations, and says a scan found no evidence of agents hacking third parties. Security investment has since increased.

The widely shared detail: a vibe-coded app included a fail-open vulnerability that silently disabled authentication.

Related event: METR Discloses Security Incidents as Agent Bug Leaks API Key, Costing $600K(5 posts)→

Original post →

More from Safety

Safety channel →