- AI safety non-profit METR suffered two security incidents in 2026 involving attempted system access and stolen API keys.
- A March incident saw attackers steal an API key from a publicly accessible “vibe-coded” app, consuming roughly $600,000 in free credits.
- A May campaign involved systematic probing of METR’s infrastructure, including a failed attempt to exploit a bug in a public transcript viewer.
METR, a research non-profit evaluating frontier AI models, disclosed two security incidents in 2026 where external actors attempted unauthorized system access. The organization stated no sensitive information was accessed and the attacks did not involve AI agents breaking its evaluations.
In March, attackers stole an API key from a researcher’s public EC2 instance, which suffered a “fail-open vulnerability” that silently disabled authentication. The attacker found the instance by scanning recently-registered websites for “vibe-coded” sites with keywords relating to LLMs, then prompted an agent to reveal the API key. The stolen credentials consumed a significant amount of credits on public models over three weeks, which would have cost approximately $600,000 had the provider not provided them for free.
The May incident involved a “sustained external attack campaign” from a likely financially motivated actor. Attackers systematically probed METR’s infrastructure, using agents to automate vulnerability discovery through credential stuffing, OAuth token grants, and phishing attempts. Around the same time, METR inadvertently exposed a read-only SQL query mechanism in its public transcript viewer.
A bug in the query component could have allowed access to unpublished evaluation data, and the database “accidentally included” sensitive model data. An independent security researcher discovered and reported the issue, leading to the API being taken offline. While attackers probed the endpoint, evidence shows no indication they discovered the exploit or accessed non-public data.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
