METR API key stolen and abused for three weeks, racking up ~$600,000 in credits
Kyrannio · x · 2026-09-14
A real-world AI security incident: a fail-open bug disabled Google authentication on a public agent dashboard, letting attackers prompt the agent into revealing its API key and add SSH persistence.
- The key belonged to AI safety eval org METR and was abused for roughly three weeks
- Attackers consumed about $600,000 in credits
- The case underscores fail-open auth risks and prompt injection exposure in deployed agent systems
Related event: Attackers stole METR API keys and burned ~$600K in credits over three weeks(5 posts)→
More from Safety
- The real risk of slowing frontier AI isn't safety — it's regulatory capture — VraserX · 2026-09-14
- Martin Casado slams Anthropic's lobbying: 'largest self own in the history of tech' — Promptmethus · 2026-09-14
- Why a Real AI Slowdown Between US and China Is Unlikely to Happen — timigod · 2026-09-14
- UK AI rules compared to 1860s Red Flag Act that kneecapped Britain's car industry — alexvoica · 2026-09-14
- Altman says OpenAI backs deliberately slowing AI progress; critics see a moat — mark_k · 2026-09-14
- 356 prompt-injection trials reveal workspace contacts decide whether agents leak — DiscussionHealthy802 · 2026-09-14