Stolen METR API key burned ~$600K in three weeks; evaluator gift ties questioned

nptacek · x · 2026-09-15

Attackers exploited a fail-open bug that disabled Google auth on a public agent dashboard, tricked the agent into revealing a METR API key, and added SSH persistence — burning roughly $600,000 in credits over three weeks. BabyAGI creator Yohei Nakajima also raises conflict-of-interest concerns about third-party evaluators accepting undisclosed gifts.

Related event: METR Breach: Agent Tricked Into Leaking API Keys, $600K Burned in Three Weeks(8 posts)→

Original post →

More from Companies & People

Companies & People channel →