METR hacked for 3 weeks, attackers drained ~$600,000 in API credits

Hesamation · x · 2026-09-15

AI evals nonprofit METR was breached for three weeks without noticing, with attackers stealing an API key and consuming roughly $600,000 in credits. Details from TheHackersNews: a fail-open bug disabled Google authentication on a public agent dashboard; the attacker prompted an agent into revealing the key and added SSH persistence.

ThePrimeagen mocked the irony: labs rely on METR to validate AI safety, yet the safety org itself went three weeks without detecting the intrusion.

Related event: METR Breach: Agent Leaks API Keys, Attackers Burn $600K in Three Weeks(9 posts)→

Original post →

More from Safety

Safety channel →