Stolen METR API key burned ~$600,000 in credits over three weeks via fail-open auth bug
nptacek · x · 2026-09-15
Per TheHackersNews, attackers stole an API key from eval org METR and burned roughly $600,000 in credits over three weeks. The entry point: a public agent dashboard had a fail-open bug that disabled Google authentication. The attacker used prompt injection to make an agent reveal the key, then added SSH persistence.
In the quoted retweet, @EMostaque notes that eval orgs like METR will face nation-state-level attacks and need both world-class AI talent and world-class cybersecurity — fields that, in his experience, barely overlap.
Related event: METR Loses $600K After API Keys Stolen via Fail-Open Flaw(7 posts)→
More from AGI Musings
- Thought experiment: should a basement-built frontier-level LLM be shut down? — pickover · 2026-09-15
- Investor: frontier AI labs won't slow compute spend, no onerous regulation for 2 years — firstadopter · 2026-09-15
- Close to a huge math breakthrough, then scooped by AI: what it means for open science — ScottNover · 2026-09-15
- Agent-to-agent communication will kill email, argues early Instinct user — manosaie · 2026-09-15
- Marty Cagan revisits 20 years: 10 product management beliefs he no longer holds — rseroter · 2026-09-15
- Why mathematicians resist AI proofs — and why it's not just gatekeeping — rbhar90 · 2026-09-15