About $600,000 in model‑inference credits were consumed by an unknown attacker after they stole an API key from a publicly accessible experiment, METR said — a loss that only evaporated because the model provider waived the bill.
March incident: stolen API key, exposed EC2 instance, and $600,000 in credits
METR reported that in March 2026 an API key for inference on publicly available models was stolen from a researcher’s personal EC2 instance that had been intentionally made publicly accessible and protected by Google authentication. The instance ran a “vibe‑coded app” that suffered a “fail‑open vulnerability” which silently disabled authentication and left the agent orchestration dashboard exposed to the public internet for several days.
According to METR, the attacker prompted an agent to reveal its model provider API key, added an SSH key for persistent access, and used the credentials to consume a “substantial amount of credits” over a period of three weeks. METR estimated the usage would have racked up approximately $600,000 in bills but said the model provider provided the accrued credits to the non‑profit for free. METR emphasized that the researcher who used the EC2 instance had “no sensitive access.”
May campaign: automated probing, exposed SQL query, and unpublished evaluation data
In May 2026 METR observed what it described as a “sustained external attack campaign” by a “likely financially motivated threat actor” that systematically probed METR’s publicly accessible infrastructure. The campaign used heavy agent automation to discover vulnerabilities, according to METR.
At the same time METR inadvertently exposed a read‑only SQL query mechanism in its public transcript viewer. Although queries were scoped to public data by default, a bug in the component could have been exploited to access unpublished evaluation data. METR further reported that the backing database “accidentally included” sensitive model data even though it was intended to contain only non‑sensitive models. METR became aware of the issue after an independent security researcher discovered and reported it; the API was then taken offline.
METR said the attackers had probed the endpoint “in passing” as part of their broader campaign, but that the evidence shows “no indication that they discovered the exploit or accessed any non‑public data.” METR also stated that no sensitive information is believed to have been accessed across the two incidents.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildHow the attackers located and abused METR infrastructure
METR’s post‑incident analysis provides a specific picture of attacker tradecraft. For the March incident, METR said it suspects the attacker searched “recently‑registered websites (e.g., in certificate transparency lists) to find vibe‑coded sites with high‑signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys.”
In the May campaign METR observed broad automation: agents used to automate vulnerability discovery, credential stuffing against authentication providers, attempts to obtain OAuth token grants, scanning of newly deployed services, and phishing directed at staff. In the March case the actor also added an SSH key and used the stolen API key to run inference on public models for weeks.
METR's immediate fixes: updated policies, monitoring, and spend alerts
METR said it has changed several operational security practices in response. The non‑profit updated its policies governing the placement of METR credentials or data on non‑METR infrastructure or devices, improved monitoring, and added spend alerts to keys where possible. METR also noted that the illicit usage in March was not immediately obvious because it runs large‑scale evaluations and experiments that normally consume high token volumes and because there had been no caps on token spend.
METR additionally shared a version of its findings with AI companies it works with prior to public disclosure, and reiterated that the incidents “did not involve AI agents breaking into its evaluations.” The attacks have not been attributed to any known threat actor or group.
What this means for technologists and security teams, model providers, and independent researchers
- Technologists and security teams: METR’s fixes — updated credential policies, enhanced monitoring, and spend alerts — highlight concrete controls organizations running large‑scale model evaluations may prioritize after similar exposures: avoid placing credentials on third‑party or personal infrastructure, monitor for abnormal token spend, and enforce caps where possible. METR said the absence of spend caps helped the activity go unnoticed amid legitimate high token usage.
- Model providers and procurement teams: The model provider’s decision to absorb roughly $600,000 of incurred charges by providing the credits to METR underscores the potential financial impact of stolen API keys when billing and authentication controls are bypassed. METR also noted it works with AI companies and shared findings with them prior to public disclosure.
- Independent researchers and disclosure channels: The SQL exposure was discovered and reported by an independent security researcher, whose report prompted METR to take the affected API offline. That sequence demonstrates the role external reporting played in detecting one of the issues.
No sensitive information is believed to have been taken in either incident, and METR says the attacks were not the result of AI agents breaking into its evaluations. The events center attention on an operational fact METR itself flagged: publicly accessible experiments, third‑party tooling with fail‑open behavior, and the lack of token‑spend controls can combine to amplify financial and data‑exposure risk. METR’s public disclosure and its prior sharing of findings with partnered AI companies close this chapter for now — but the incidents leave open who will bear costs and operational changes when similar lapses recur.
Source: The Hacker News — Attackers Steal METR API Key and Consume AI Credits Worth About $600,000




