METR Attackers Drain $600,000 In AI Credits Arabian Post
METR said the March 2026 breach stemmed from a researcher's personal Amazon EC2 instance running an agent orchestration application that had been deliberately placed behind Google authentication. A fail-open flaw in the“vibe-coded” application silently disabled that authentication, leaving the system exposed to the public internet for several days.
The non-profit, formally Model Evaluation and Threat Research, said the compromised instance contained an API key linked to its general-access account for publicly available AI models. After finding the exposed service, the attacker prompted an agent directly to reveal the model provider's API key, added an SSH key to maintain persistent access and then used the stolen credentials for roughly three weeks.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment