Stolen METR API key burned ~$600K in credits via fail-open agent dashboard bug

GaryMarcus · x · 2026-09-02

A fail-open bug disabled Google authentication on a public agent dashboard, letting attackers prompt an agent into revealing METR's API key and adding SSH persistence. The key was abused for roughly three weeks, consuming about $600,000 in credits. Gary Marcus shared the incident as more evidence that vibe coding without security review is a real risk.

Related event: METR Discloses Security Incidents as Agent Bug Leaks API Key, Costing $600K(5 posts)→

Original post →

More from Safety

Safety channel →