Stolen METR API key burned ~$600,000 in credits over three weeks; critics mock the AI-safety eval org
AlexTensor · x · 2026-09-14
Attackers exploited a fail-open bug that disabled Google auth on a public METR agent dashboard, prompting an agent to reveal an API key and adding SSH persistence. The key was used for three weeks, burning roughly $600,000 in credits. Andrew Orlowski mocks METR's competence given Dario Amodei's reliance on the org for AI safety evaluations.
More from Safety
- Dario responds to safety critics: I'd rather be mocked than see Claude used to kill — NathanpmYoung · 2026-09-14
- Vitalik Buterin: Adversarial mechanism design could be AI safety's killer app — allisondman · 2026-09-14
- Oxford thesis proposes 'Attribution-Based Control' to tackle AI privacy and alignment risks — iamtrask · 2026-09-14
- We Unite or We Fight: The Long-Term Case for International AI Governance — danfaggella · 2026-09-14
- Cohere CEO Aidan Gomez: AI Needs Evidenced Standards, Not a Big-Lab Cartel — cohere · 2026-09-14
- OpenMined's 'network sourced' AI: models as orderly clients of private repositories — iamtrask · 2026-09-14