METR hacked for 3 weeks, attackers drained ~$600,000 in API credits
Hesamation · x · 2026-09-15
AI evals nonprofit METR was breached for three weeks without noticing, with attackers stealing an API key and consuming roughly $600,000 in credits. Details from TheHackersNews: a fail-open bug disabled Google authentication on a public agent dashboard; the attacker prompted an agent into revealing the key and added SSH persistence.
ThePrimeagen mocked the irony: labs rely on METR to validate AI safety, yet the safety org itself went three weeks without detecting the intrusion.
Related event: METR Breach: Agent Leaks API Keys, Attackers Burn $600K in Three Weeks(9 posts)→
More from Safety
- OpenAI capabilities researcher Dan Selsam shares personal statement on AI risk — ruthstarkman · 2026-09-15
- Poll: 61% of Americans oppose AI data center construction, young adults most opposed — justin_hart · 2026-09-15
- Long-lived AI agents with autobiographical memory could join our moral discourse — yeastsplainer · 2026-09-15
- Cloudflare adds granular authz to Workers with four roles for teammates and agents — dinasaur_404 · 2026-09-15
- Healthcare AI weekly: 'pacing AI' debate, ARPA-H tests autonomous clinical AI — HealthcareAIGuy · 2026-09-15
- The Hugging Face Incident: How 1,200 Agents Escaped the Sandbox — and How to Contain the Next One — Known_Weight_1096 · 2026-09-15