Stolen METR API key burned ~$600,000 in credits over three weeks via fail-open auth bug

nptacek · x · 2026-09-15

Per TheHackersNews, attackers stole an API key from eval org METR and burned roughly $600,000 in credits over three weeks. The entry point: a public agent dashboard had a fail-open bug that disabled Google authentication. The attacker used prompt injection to make an agent reveal the key, then added SSH persistence.

In the quoted retweet, @EMostaque notes that eval orgs like METR will face nation-state-level attacks and need both world-class AI talent and world-class cybersecurity — fields that, in his experience, barely overlap.

Related event: METR Loses $600K After API Keys Stolen via Fail-Open Flaw(7 posts)→

Original post →

More from AGI Musings

AGI Musings channel →