← BACK TO FEED
TAG

metr2 articles

METR Got Hacked Twice and Didn't Notice One of Them for Three Weeks

AI model testing organization METR disclosed two security incidents from early 2025: in March, an attacker exploited a fail-open authentication bug in a researcher's publicly accessible app to steal an API key, then spent three weeks consuming roughly $600,000 worth of model credits undetected. The theft went unnoticed because METR routinely uses large numbers of tokens for evaluations and the credits had been provided for free, meaning no unexpected bill was generated. A second incident in May involved a sustained attack campaign probing METR's infrastructure, including an inadvertently exposed database endpoint containing some sensitive model data, though there is no evidence any non-public information was actually accessed.

2 Sept 2026

AI Safety Org METR Got Hacked Twice. One Slip Cost $600K in API Credits.

METR, an AI safety research non-profit, disclosed two security incidents in 2026 involving unauthorised access attempts to its systems. In the first, attackers exploited a poorly secured researcher's personal server to steal an API key and consumed approximately $600,000 worth of AI credits over three weeks, going undetected due to METR's typically high token usage. In the second, attackers conducted a broad, agent-assisted campaign probing METR's infrastructure, though an inadvertently exposed database endpoint — which could have revealed sensitive model data — was ultimately not successfully exploited.

2 Sept 2026