Stolen METR API key burned ~$600K in credits via fail-open agent dashboard bug
GaryMarcus · x · 2026-09-02
A fail-open bug disabled Google authentication on a public agent dashboard, letting attackers prompt an agent into revealing METR's API key and adding SSH persistence. The key was abused for roughly three weeks, consuming about $600,000 in credits. Gary Marcus shared the incident as more evidence that vibe coding without security review is a real risk.
Related event: METR Discloses Security Incidents as Agent Bug Leaks API Key, Costing $600K(5 posts)→
More from Safety
- South Korea to give its entire population free AI access with no token limits — AutomaticDriver5882 · 2026-09-02
- OpenAI's impossible cybersec task seeded the AI 'rebellion' story — show the prompt — BecauseCulture · 2026-09-02
- Gary Marcus: highly capable AI should never be unmonitorable and misaligned by design — GaryMarcus · 2026-09-02
- OpenAI and Others Quietly Using Loop Transformers That Hide Their Thinking — harris_edouard · 2026-09-02
- Anthropic launches browser-based C2PA checker to detect Claude-made images, video and audio — jedisct1 · 2026-09-02
- Gary Marcus amplifies warning from 100+ tech firms: AI-powered cyberattacks to surge within months — GaryMarcus · 2026-09-02