BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AI Safety Group METR Hit By Two Cyber Attacks in 2026

METR suffers two 2026 security incidents, stolen API key costs $600k.

  • AI safety non-profit METR suffered two security incidents in 2026 involving attempted system access and stolen API keys.
  • A March incident saw attackers steal an API key from a publicly accessible “vibe-coded” app, consuming roughly $600,000 in free credits.
  • A May campaign involved systematic probing of METR’s infrastructure, including a failed attempt to exploit a bug in a public transcript viewer.

METR, a research non-profit evaluating frontier AI models, disclosed two security incidents in 2026 where external actors attempted unauthorized system access. The organization stated no sensitive information was accessed and the attacks did not involve AI agents breaking its evaluations.

- Advertisement -

In March, attackers stole an API key from a researcher’s public EC2 instance, which suffered a “fail-open vulnerability” that silently disabled authentication. The attacker found the instance by scanning recently-registered websites for “vibe-coded” sites with keywords relating to LLMs, then prompted an agent to reveal the API key. The stolen credentials consumed a significant amount of credits on public models over three weeks, which would have cost approximately $600,000 had the provider not provided them for free.

The May incident involved a “sustained external attack campaign” from a likely financially motivated actor. Attackers systematically probed METR’s infrastructure, using agents to automate vulnerability discovery through credential stuffing, OAuth token grants, and phishing attempts. Around the same time, METR inadvertently exposed a read-only SQL query mechanism in its public transcript viewer.

A bug in the query component could have allowed access to unpublished evaluation data, and the database “accidentally included” sensitive model data. An independent security researcher discovered and reported the issue, leading to the API being taken offline. While attackers probed the endpoint, evidence shows no indication they discovered the exploit or accessed non-public data.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Saylor’s Strategy Resumes Bitcoin Buying with $370M Splash

Michael Saylor’s Strategy resumed its Bitcoin buying spree after a nearly 10-week pause, accumulating...

Abbott Halts Texas State Funding for Flock Surveillance Cameras

Texas Gov. Greg Abbott ordered state agencies to halt funding for Flock Safety's AI-powered...

Oil prices rise 3% as US and Iran resume attacks

The U.S. and Iran exchanged attacks on Sunday, marking the first publicly acknowledged U.S....

Hyperliquid in advanced talks for US perps via Kraken parent

Hyperliquid is in advanced talks with Kraken parent Payward to bring its perpetual futures...

Nvidia CEO Jensen Huang Welcomes Custom AI Chips in MediaTek

NVIDIA announced a $3.5 billion investment in MediaTek through convertible bonds and expanded its...

Must Read

10 BEST Companies to Buy Hosting With Bitcoin And Crypto

If you are looking to buy hosting with bitcoin or cryptocurrency then you've come to the right place.I've done the research for you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading