Attackers Stole METR API Key and Burned ~$600,000 in AI Credits Over Three Weeks

beffjezos · x · 2026-09-14

METR, the nonprofit that evaluates frontier AI models, disclosed two security incidents. In March 2026, a fail-open bug silently disabled Google auth on a researcher's public agent dashboard, letting attackers prompt an agent into revealing an API key, add SSH persistence, and consume $600,000 in inference credits over three weeks. In May, attackers probed its infrastructure; no sensitive data was accessed. beffjezos (Guillaume Verdon) mocked it as security theatre, arguing only local open-source models offer real safety.

Related event: Attackers stole METR API keys and burned ~$600K in credits over three weeks(5 posts)→

Original post →

More from AGI Musings

AGI Musings channel →