Stolen METR API key burned ~$600,000 in credits over three weeks; critics mock the AI-safety eval org

AlexTensor · x · 2026-09-14

Attackers exploited a fail-open bug that disabled Google auth on a public METR agent dashboard, prompting an agent to reveal an API key and adding SSH persistence. The key was used for three weeks, burning roughly $600,000 in credits. Andrew Orlowski mocks METR's competence given Dario Amodei's reliance on the org for AI safety evaluations.

Original post →

More from Safety

Safety channel →