Stolen METR API key burned ~$600,000 in three weeks via a fail-open auth bug

nptacek · x · 2026-09-14

Attackers exploited a fail-open bug that disabled Google authentication on a public agent dashboard, prompted an agent into revealing METR's API key, and added SSH persistence—then spent roughly $600,000 in credits over three weeks. The report was amplified by a16z's Martin Casado, spotlighting agent deployment security failures.

Related event: Attackers stole METR API keys and burned ~$600K in credits over three weeks(5 posts)→

Original post →

More from Safety

Safety channel →