A stolen AI API key has turned into an expensive security lesson for METR, a nonprofit that evaluates the capabilities and risks of frontier AI models.
METR disclosed two security incidents in 2026 involving attempts to gain unauthorized access to its systems. While the organization said there is no evidence that sensitive information was accessed, the incidents show how quickly exposed AI infrastructure can become a target.
The first incident happened in March. A METR researcher was running AI agents from a personal Amazon EC2 instance. The system hosted an agent-orchestration dashboard that was intentionally accessible over the internet and protected by Google authentication.
But the application contained a “fail-open” authentication vulnerability, which silently disabled the protection and left the dashboard exposed for several days.
METR suspects attackers discovered the system by searching recently registered websites and certificate-transparencyrecords for sites containing keywords related to LLMs and AI agents.
Once they found the exposed system, the attackers prompted the AI agent to reveal its model-provider API key. They then added their own SSH key for persistent access and used the stolen credentials to run publicly available AI models for approximately three weeks.
The resulting usage would have cost around $600,000 at commercial rates. METR did not have to pay that amount because the model provider had supplied the credits to the nonprofit for free.
The activity also went undetected for some time. METR routinely conducts large-scale AI evaluations that consume significant amounts of tokens, and the affected API key had no spending cap.
In May, METR observed a more sustained campaign apparently aimed at gaining unauthorized access to frontier AI models. Attackers systematically probed public infrastructure, using techniques including credential stuffing, attempted OAuth token grants, scanning newly deployed services and phishing employees. They also appeared to use AI agents to automate vulnerability discovery.
Around the same period, METR discovered that its public transcript viewer had an exposed read-only SQL query mechanism. A bug could potentially have allowed attackers to access unpublished evaluation data. The database also accidentally contained sensitive model data.
An independent researcher reported the issue, and METR took the API offline. The organization said there was no evidence attackers exploited the vulnerability or accessed non-public data.
Let’s refine your stalking skills; go through our Instagram and LinkedIn.