AI Agent Leaks $600,000 API Credential Due to Config Error
rohanpaul_ai · x · 2026-09-02
METR disclosed a security incident where an AI agent running on an EC2 instance exposed a $600,000 API credential due to a misconfigured dashboard that silently failed and disabled Google authentication. Attackers found the service via certificate-transparency lists and directly prompted the agent for the credentials. METR confirmed no sensitive data was accessed and has bolstered security measures.
Related event: METR AI Agent Bug Leaks API Keys Worth $600K(2 posts)→
More from coding & agent
- Developers tire of frequent model switches, prefer stable improvements like Claude Code — ivan_bezdomny · 2026-09-02
- Claude-BugHunter: Open-Source Skill Bundle With 83 Skills and 681 Disclosure Patterns — tom_doerr · 2026-09-02
- Full Life Sim Built with One Prompt Using Claude Fable 5.1 — CurieuxExplorer · 2026-09-02
- Is Over-Verification in Coding Agents a Runtime-State Problem? — klahmestiyo · 2026-09-02
- Nous Research Launches Portal to Unify Agent Ecosystem — Teknium · 2026-09-02
- Implementing Q-learning in a GDevelop platformer game — tristanbob · 2026-09-02