Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Whistle-Blower Says Trump Officials Are Defying Court Orders on Voting by Mail

    September 1, 2026

    TP-Link’s first Wi-Fi 8 router is almost here

    September 1, 2026

    Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

    September 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Whistle-Blower Says Trump Officials Are Defying Court Orders on Voting by Mail
    • TP-Link’s first Wi-Fi 8 router is almost here
    • Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
    • UK’s National Crime Agency Freezes $13.6M of Premier League Money in Sorare Probe: Report
    • Rocky planets may have formed just 100 million years after the Big Bang
    • UN fund for sharing biodiversity benefits struggles for attention — and money
    • Sarah Rogers: The Trump State Department Free Speech Ideologue Taking on Europe
    • Unpacking claims about funding cuts to Dolly Parton’s Imagination Library
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 1, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 01, 2026Cyber Attack / Artificial Intelligence

    METR (short for Model Evaluation and Threat Research and pronounced “Meter”), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered “two notable security incidents” where external actors attempted to gain unauthorized access to its systems.

    No sensitive information is believed to have been accessed as a result of these incidents, it said, adding that a version of its findings was shared with AI companies it works with prior to public disclosure. The attacks have not been attributed to any known threat actor or group, nor did they involve AI agents breaking into its evaluations.

    “In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” METR said. “In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.”

    The March Incident

    According to METR, one of its researchers with no sensitive access is said to have used agents running on a personal EC2 instance that was intentionally made publicly accessible behind Google authentication. The instance contained an API key for METR’s general-access (public models) account.

    Cybersecurity

    However, the “vibe-coded app” suffered from a “fail-open vulnerability” that silently disabled authentication, causing the agent orchestration dashboard to be exposed to the public internet for several days.

    “From our analysis, we suspect that the attacker found the instance by looking through recently-registered websites (e.g., in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,” METR explained.

    Once the system was identified, the threat actor prompted an agent directly to reveal its model provider API key, added an SSH key for persistent access, and used the stolen credentials to consume a significant amount of API credits on publicly-available models over a period of three weeks.

    METR said the accrued credits would have racked up approximately $600,000 in bills had it not been provided to the non-profit for free by the model provider. It did not name the AI company.

    It also noted that the illicit usage was not immediately caught because it runs large-scale evaluations and experiments that typically consume a high volume of tokens and the fact that there were no caps on token spend. Following the incident, METR said it has updated its security policies around putting METR credentials or data on non-METR infrastructure or devices, improved monitoring, and added spend alerts to keys where possible.

    The May Incident

    The second attack observed in May 2026 has been described as a “sustained external attack campaign” orchestrated by a likely financially motivated threat actor to obtain unlawful access to frontier AI models.

    “We observed the attackers systematically probing our publicly accessible infrastructure, with heavy use of agents to automate vulnerability discovery, including by credential stuffing authentication providers, attempting OAuth token grants, scanning newly deployed services, and attempting to phish staff,” METR said.

    Cybersecurity

    Around the same time, the research entity said it inadvertently exposed a read-only SQL query mechanism built into its public transcript viewer. Although the queries were scoped to public data by default, a bug in the component could have been exploited to access unpublished evaluation data.

    In addition, the database “accidentally included” sensitive model data, despite the fact that it was supposed to contain only data from non-sensitive models. METR said it became aware of the issue only after an independent security researcher discovered and reported it, resulting in the API being taken offline.

    “The attackers had probed this endpoint in passing as part of their broader campaign, but the evidence shows no indication that they discovered the exploit or accessed any non-public data,” METR said.

    API Attackers Consume Credits key METR Steal worth
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    9.5 Million Impacted by Aesto Health Data Breach

    What Is Worth Preserving: Rupture On Remains, Decay, And The Collector’s Dilemma

    Recently patched PaperCut zero-days used in data theft attacks

    OpenAI confirms ChatGPT outage as users report errors

    PaperCut Exploitation Escalates to Active Intrusions

    Microsoft Exchange Online outage causes email failures, auth issues

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Whistle-Blower Says Trump Officials Are Defying Court Orders on Voting by Mail

    September 1, 2026

    TP-Link’s first Wi-Fi 8 router is almost here

    September 1, 2026

    Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

    September 1, 2026

    UK’s National Crime Agency Freezes $13.6M of Premier League Money in Sorare Probe: Report

    September 1, 2026
    Latest Posts

    The future of AI hinges on openness and cooperation. China and Britain can gain much by working together | Zheng Zeguang

    July 30, 2026

    Drought declared for whole of Wales amid sustained high temperatures

    July 30, 2026

    This 4,000-year-old city defied the rules of history

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Whistle-Blower Says Trump Officials Are Defying Court Orders on Voting by Mail

    September 1, 2026

    TP-Link’s first Wi-Fi 8 router is almost here

    September 1, 2026

    Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

    September 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.