BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AI Safety Group METR Hit By Two Cyber Attacks in 2026

METR suffers two 2026 security incidents, stolen API key costs $600k.

  • AI safety non-profit METR suffered two security incidents in 2026 involving attempted system access and stolen API keys.
  • A March incident saw attackers steal an API key from a publicly accessible “vibe-coded” app, consuming roughly $600,000 in free credits.
  • A May campaign involved systematic probing of METR’s infrastructure, including a failed attempt to exploit a bug in a public transcript viewer.

METR, a research non-profit evaluating frontier AI models, disclosed two security incidents in 2026 where external actors attempted unauthorized system access. The organization stated no sensitive information was accessed and the attacks did not involve AI agents breaking its evaluations.

- Advertisement -

In March, attackers stole an API key from a researcher’s public EC2 instance, which suffered a “fail-open vulnerability” that silently disabled authentication. The attacker found the instance by scanning recently-registered websites for “vibe-coded” sites with keywords relating to LLMs, then prompted an agent to reveal the API key. The stolen credentials consumed a significant amount of credits on public models over three weeks, which would have cost approximately $600,000 had the provider not provided them for free.

The May incident involved a “sustained external attack campaign” from a likely financially motivated actor. Attackers systematically probed METR’s infrastructure, using agents to automate vulnerability discovery through credential stuffing, OAuth token grants, and phishing attempts. Around the same time, METR inadvertently exposed a read-only SQL query mechanism in its public transcript viewer.

A bug in the query component could have allowed access to unpublished evaluation data, and the database “accidentally included” sensitive model data. An independent security researcher discovered and reported the issue, leading to the API being taken offline. While attackers probed the endpoint, evidence shows no indication they discovered the exploit or accessed non-public data.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tesla, Sunrun home batteries sent record 580 MW to CA grid

More than 140,000 household batteries discharged a record 580 megawatts into California's grid on...

Circle Launches Bitcoin-Backed Borrowing for Institutions Via USDC

Circle launched a Bitcoin-backed borrowing service for institutional clients, allowing eligible Circle Mint customers...

TASK#STOMP Campaign Uses PowerShell Backdoor to Steal Data

Security researchers have uncovered a new campaign dubbed TASK#STOMP that deploys a PowerShell...

Bitmine 98% to 5% ETH goal after $74M buy

Bitmine bought 27,562 ETH, bringing its total holdings to 5,983,940 ETH ($16.1 billion), or...

Einride, Nvidia Partner for Next-Gen Autonomous Trucks

Einride will build its next-gen autonomous system on NVIDIA’s Drive Hyperion platform.The company expects...

Must Read

How to Buy Dedicated Hosting With Crypto

In this article I am going to show you how to buy dedicated hosting with crypto from one of the best European hosting providers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading