Tuesday, 02 January 2024 12:17 GMT

METR Attackers Drain $600,000 In AI Credits Arabian Post


(MENAFN- The Arabian Post) clearfix">Attackers stole an API key from AI safety research organisation METR and used it for three weeks to consume model credits worth about $600,000, the group has disclosed.

METR said the March 2026 breach stemmed from a researcher's personal Amazon EC2 instance running an agent orchestration application that had been deliberately placed behind Google authentication. A fail-open flaw in the“vibe-coded” application silently disabled that authentication, leaving the system exposed to the public internet for several days.

The non-profit, formally Model Evaluation and Threat Research, said the compromised instance contained an API key linked to its general-access account for publicly available AI models. After finding the exposed service, the attacker prompted an agent directly to reveal the model provider's API key, added an SSH key to maintain persistent access and then used the stolen credentials for roughly three weeks.

MENAFN03092026000152002308ID1111615959



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story