METR API key stolen and abused for three weeks, racking up ~$600,000 in credits

Kyrannio · x · 2026-09-14

A real-world AI security incident: a fail-open bug disabled Google authentication on a public agent dashboard, letting attackers prompt the agent into revealing its API key and add SSH persistence.

Related event: Attackers stole METR API keys and burned ~$600K in credits over three weeks(5 posts)→

Original post →

More from Safety

Safety channel →