METR reports API-key theft that drained $600K in free model credits and a later probing attack
The Model Evaluation and Threat Research (METR) nonprofit revealed that an attacker stole an API key in March, using it to consume roughly $600,000 of free public-model credits over three weeks, and that a separate May incident involved probing of its public infrastructure without accessing private data.
In March 2026, METR disclosed that a misconfigured EC2 instance left publicly accessible behind Google authentication contained an API key for its public-model account. An attacker discovered the instance via certificate-transparency listings, extracted the key, installed an SSH key for persistence, and over three weeks consumed about $600,000 in free public-model credits. METR did not flag the usage because its routine evaluations already generate large token counts and the credits were provided at no cost, leaving no billing alerts.
A second incident in May involved a coordinated external campaign that probed METR's publicly exposed infrastructure, attempted credential stuffing, OAuth token grants, and briefly exposed a read-only SQL query endpoint, though no private evaluation data was accessed. The flaw was reported by a bug-hunter who received a bounty, prompting METR to take the API offline and move public services to an isolated production environment. The nonprofit has upgraded its security protocols, hired a security lead, and plans to expand its security team.
Why it matters
The breaches show how misconfigured cloud resources can enable costly abuse of AI services and highlight the need for stronger security controls.
In this story
