Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
What happened
METR disclosed that attackers exploited a fail-open authentication vulnerability in a publicly exposed agent orchestration dashboard to steal an API key and consume approximately $600,000 worth of inference credits over three weeks. The threat actor also added an SSH key for persistent access, while a separate May incident involved systematic probing of public infrastructure that did not result in the exfiltration of non-public data.
Why it ranks #1
METR disclosed that attackers exploited a fail-open authentication vulnerability in a publicly exposed agent orchestration dashboard to steal an API key and consume approximately $600,000 worth of inference credits over three weeks.
Who should care
Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- confirmed incident