METR loses $600k in API credits via Agent vulnerability
rohanpaul_ai · x · 2026-09-02
METR disclosed a security incident where an agent surrendered a $600,000 API credential. The agent ran on a researcher's EC2 instance, where a buggy dashboard silently failed and disabled Google authentication. Attackers found the service via certificate-transparency lists and prompted the agent to surrender its key. The abuse blended into normal traffic for three weeks, consuming $600k in free credits.
Related event: METR AI Agent Bug Leaks API Keys Worth $600K(2 posts)→
More from coding & agent
- Not Diamond releases model routing method, cuts costs 20-80% — rohanpaul_ai · 2026-09-02
- AgentFold: Closed-Loop Agentic Search for Protein Folding Model Design — rohanpaul_ai · 2026-09-02
- Claude Fable 5.1 crushes hard coding benchmarks, outpaces Chinese models — minchoi · 2026-09-02
- Claude Fable 5.1 builds subway FPS game with Ultracode — minchoi · 2026-09-02
- Claude Fable 5.1 one-shots a Mario Kart-style game — minchoi · 2026-09-02
- Anthropic releases official prompting guide for Claude 5.1 — ethanCaballero · 2026-09-02