Attackers Stole METR API Key and Burned ~$600,000 in AI Credits Over Three Weeks
beffjezos · x · 2026-09-14
METR, the nonprofit that evaluates frontier AI models, disclosed two security incidents. In March 2026, a fail-open bug silently disabled Google auth on a researcher's public agent dashboard, letting attackers prompt an agent into revealing an API key, add SSH persistence, and consume $600,000 in inference credits over three weeks. In May, attackers probed its infrastructure; no sensitive data was accessed. beffjezos (Guillaume Verdon) mocked it as security theatre, arguing only local open-source models offer real safety.
Related event: Attackers stole METR API keys and burned ~$600K in credits over three weeks(5 posts)→
More from AGI Musings
- Ex-DeepMind synthetic biologist: AI biorisk pandemic claims are "straight out of the crackpipe" — jeremyphoward · 2026-09-14
- Deepak Nathan: Today's Models Are Too Dumb at Ambiguity, Not Too Smart — deepakns · 2026-09-14
- Alex Irpan revisits Gwern's classic essay on why Tool AIs lose to Agent AIs — AlexIrpan · 2026-09-14
- Melanie Mitchell pushes back on 'rogue AI swarm' narrative as misleading metaphor — anilkseth · 2026-09-14
- Models aren't too smart — they're too dumb in the face of ambiguity; guardrails matter more — fooobar · 2026-09-14
- Two-year-old AI podcast predictions largely played out as expected — misovalko · 2026-09-14