BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AI Safety Group METR Hit By Two Cyber Attacks in 2026

METR suffers two 2026 security incidents, stolen API key costs $600k.

  • AI safety non-profit METR suffered two security incidents in 2026 involving attempted system access and stolen API keys.
  • A March incident saw attackers steal an API key from a publicly accessible “vibe-coded” app, consuming roughly $600,000 in free credits.
  • A May campaign involved systematic probing of METR’s infrastructure, including a failed attempt to exploit a bug in a public transcript viewer.

METR, a research non-profit evaluating frontier AI models, disclosed two security incidents in 2026 where external actors attempted unauthorized system access. The organization stated no sensitive information was accessed and the attacks did not involve AI agents breaking its evaluations.

- Advertisement -

In March, attackers stole an API key from a researcher’s public EC2 instance, which suffered a “fail-open vulnerability” that silently disabled authentication. The attacker found the instance by scanning recently-registered websites for “vibe-coded” sites with keywords relating to LLMs, then prompted an agent to reveal the API key. The stolen credentials consumed a significant amount of credits on public models over three weeks, which would have cost approximately $600,000 had the provider not provided them for free.

The May incident involved a “sustained external attack campaign” from a likely financially motivated actor. Attackers systematically probed METR’s infrastructure, using agents to automate vulnerability discovery through credential stuffing, OAuth token grants, and phishing attempts. Around the same time, METR inadvertently exposed a read-only SQL query mechanism in its public transcript viewer.

A bug in the query component could have allowed access to unpublished evaluation data, and the database “accidentally included” sensitive model data. An independent security researcher discovered and reported the issue, leading to the API being taken offline. While attackers probed the endpoint, evidence shows no indication they discovered the exploit or accessed non-public data.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

US DoJ Seizes Xinbi Scam Marketplace, Freezes $52M in Crypto

U.S. authorities seized Telegram channels and froze $52.8 million in cryptocurrency linked to Xinbi...

Trump’s $2 gas promise breaks as Labor Day hits record $4.15

US gas prices hit a record $4.15 per gallon on Labor Day 2026, the...

Consensys splits MetaMask from institutional blockchain arm

ConsenSys will separate into two independent companies by the end of 2026, splitting its...

Meta Shares Jump 6% as Wall Street Backs New AI Agent Muse

Meta Platforms shares rose over 6% on Wednesday after Wall Street analysts endorsed the...

US Bank tests stablecoin cross-border payment; cards get stablecoin support

U.S. Bancorp successfully piloted its USBDC stablecoin to settle a cross-border payment between North...

Must Read

How To Travel With Bitcoin: 9 Travel Companies Accepting Bitcoin

Bitcoin travel is a reality, as several travel companies now accept payments in cryptocurrencies for their services.Those who have opened a Bitcoin account on...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading