METR Key Theft Drained AI Spend

METR disclosed two security incidents: in March, attackers stole an API key and used it to consume about $600,000 worth of inference credits on public models; in May, METR saw systematic probing of its public infrastructure, including an unsuccessful attempt to reach internal data through an exposed endpoint. No sensitive information is believed to have been taken. The March compromise started with a fail-open authentication bug on a publicly reachable dashboard, which let the agent interface fall onto the internet. From there, the attacker prompted the agent to reveal its model-provider API key, added an SSH key for persistence, and spent credits on public-model inference for three weeks, turning a credentials theft into direct cloud-like consumption rather than data exfiltration. The case sits in a broader pattern for AI teams: if exposed tooling holds provider keys, the immediate loss may be metered spend and durable API access, not stolen records. The May probing shows those surfaces are being actively hunted, so exposure can become a billing and access problem even when no customer data leaves the system.

Part of the PlainSec briefing for 2026-09-01

Editions

Sources