Top Highlights
- Attackers exploited a misconfigured API key and a remote code execution vulnerability in METR’s publicly accessible infrastructure, stealing API credits worth nearly $600,000 over three weeks.
- A sustained campaign involved credential stuffing, vulnerability scanning, and phishing attempts to gain uncontrolled access to frontier AI models and sensitive evaluation data.
- An unintentional exposure of a read-only SQL query mechanism risked leaking unpublished evaluation data and limited sensitive model information, though no data was ultimately accessed.
Threat, Techniques, and Targets
The threat involves attackers stealing API keys from METR, a non-profit group that studies AI models. In March 2026, attackers took an API key used for public AI models. They used a vulnerable, publicly accessible cloud instance that was not well protected. This allowed them to prompt an agent to reveal its API key. They then used the stolen key to consume a large number of AI credits, worth about $600,000.
In May 2026, attackers continued their efforts. They probed METR’s public infrastructure for weaknesses. They used automated tools and credential stuffing to find vulnerabilities. They also attempted to access internal data through an exposed API and used phishing tactics against staff. This campaign aimed to access AI models and sensitive data. METR’s targets were its public AI evaluation systems and infrastructure.
Impact, Security Implications, and Remediation
The primary impact was significant financial loss due to API credit consumption, valued at around $600,000. Luckily, no sensitive information was accessed in these incidents. The attacks show the risk of weak security settings on cloud instances and exposed endpoints. They also reveal the danger of unchecked access to AI resources and models.
The security implications raise concerns about protecting API keys and cloud infrastructure. It is vital to secure all endpoints, restrict access, and monitor for unusual activity. Once METR discovered the breaches, it improved security policies. It added protections like better credential management, monitoring, and spend alerts.
For advice on specific security measures, organizations should contact their cloud service provider or relevant vendor. It is recommended to review access controls, implement detection systems, and ensure proper configuration of public services to prevent similar incidents.
Discover More Technology Insights
Learn how the Internet of Things (IoT) is transforming everyday life.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
