Stolen METR API key burned ~$600K in three weeks; evaluator gift ties questioned
nptacek · x · 2026-09-15
Attackers exploited a fail-open bug that disabled Google auth on a public agent dashboard, tricked the agent into revealing a METR API key, and added SSH persistence — burning roughly $600,000 in credits over three weeks. BabyAGI creator Yohei Nakajima also raises conflict-of-interest concerns about third-party evaluators accepting undisclosed gifts.
More from Companies & People
- Jensen Huang reacts to Coxon whistleblower revelations — JFPuget · 2026-09-15
- Jensen Huang at All In Summit discusses open models and Hugging Face acquisition — DynamicWebPaige · 2026-09-15
- Robotics commentator Herbert joins RoboStrategy to host new robotics podcast — Rewkang · 2026-09-15
- Naveen Rao to speak at All-In Summit, touting anti-doomer narrative — geoffwolfe · 2026-09-15
- Sarah Hooker: Labs can leverage your IP even if you opt out of training data — sarahookr · 2026-09-15
- Modal unveils Runtime speaker lineup spanning AI infra, science and robotics — charles_irl · 2026-09-15