Stolen METR API key burned ~$600,000 in three weeks via a fail-open auth bug
nptacek · x · 2026-09-14
Attackers exploited a fail-open bug that disabled Google authentication on a public agent dashboard, prompted an agent into revealing METR's API key, and added SSH persistence—then spent roughly $600,000 in credits over three weeks. The report was amplified by a16z's Martin Casado, spotlighting agent deployment security failures.
Related event: Attackers stole METR API keys and burned ~$600K in credits over three weeks(5 posts)→
More from Safety
- The real risk of slowing frontier AI isn't safety — it's regulatory capture — VraserX · 2026-09-14
- Martin Casado slams Anthropic's lobbying: 'largest self own in the history of tech' — Promptmethus · 2026-09-14
- Why a Real AI Slowdown Between US and China Is Unlikely to Happen — timigod · 2026-09-14
- UK AI rules compared to 1860s Red Flag Act that kneecapped Britain's car industry — alexvoica · 2026-09-14
- Altman says OpenAI backs deliberately slowing AI progress; critics see a moat — mark_k · 2026-09-14
- 356 prompt-injection trials reveal workspace contacts decide whether agents leak — DiscussionHealthy802 · 2026-09-14