METR API Key Theft Led to $600K Cloud Credit Loss

Stolen API key fuels $600k AI credit abuse after fail-open exposure

In a concerning event for the AI and cybersecurity community, METR, an AI model evaluation non-profit, suffered a significant breach when attackers stole an API key and used it to consume around $600,000 worth of cloud credits. The METR API key theft incident highlights the risks associated with exposed cloud resources, fail-open authentication, and insufficient monitoring. The breach went undetected for several weeks, underlining the need for robust secrets management and proactive alerting.

How the METR API Key Theft Happened

The incident began in March 2026, when a METR researcher was running agents on a personal Amazon EC2 instance. This instance, intended for model testing, was left publicly accessible but protected behind Google authentication. However, due to a fail-open bug in a “vibe-coded app,” authentication was inadvertently disabled. This effectively exposed the system to the public internet for several days, creating a window of opportunity for attackers.

The attackers are believed to have discovered the instance by scanning recently registered websites, particularly those with keywords associated with large language models (LLMs) or agent-based systems. Once they found the exposed app, the attackers interacted with the agent to prompt it to reveal its model provider API key. With this sensitive credential in hand, the attackers also added an SSH key to ensure persistent access.

  • Timeline: The initial compromise occurred in March 2026 and persisted for approximately three weeks.
  • Attack Method: Exploiting a fail-open bug, prompting agents for secrets, and maintaining access via SSH keys.
  • Products/Systems Affected: A personal EC2 instance running METR agents, exposed via a publicly accessible app.
  • Attackers’ Goal: To obtain and exploit API keys for public AI model inference.

During this period, the attackers used the stolen API key to consume public model credits worth an estimated $600,000. Fortunately for METR, these credits were provided for free by a model developer, so the non-profit did not face a direct financial loss. Still, the scale of the illicit activity was significant and went unnoticed for an extended period.

Why the Attack Went Undetected for Weeks

One of the most alarming aspects of the METR API key theft is how long the malicious activity remained undetected. METR regularly conducts high-volume AI model evaluations, which means that encountering unusual API errors or rate limits is not uncommon for their team. This operational reality masked the attack, as the high usage patterns did not immediately stand out as suspicious. In addition, because the tokens were provided free of charge, there was no large bill or financial alert to trigger an investigation.

Another contributing factor was the lack of spend limits or alerting mechanisms on the specific API keys in question. At the time of the breach, it was not possible to set a cap on how much could be spent using the compromised key, leaving the door open for extensive, undetected abuse.

  • High baseline usage masked abnormal activity
  • No billing alerts due to free credits
  • No spend limits or automated alerting for API key abuse

Subsequent Probing and the May 2026 Attack Attempt

The METR API key theft was not the end of malicious activity targeting the organisation. In May 2026, METR identified a sustained attack campaign against its public infrastructure. The attackers, believed to be financially motivated, systematically probed METR’s systems in search of additional access paths, including to sensitive “frontier models.” The attack included:

  • Automated vulnerability scanning of publicly accessible endpoints
  • Credential stuffing attacks against authentication providers
  • Attempts to obtain OAuth token grants
  • Scanning of newly deployed services for misconfigurations
  • Phishing campaigns targeting METR staff

Although this second wave of attacks did not result in unauthorised access to internal data, it demonstrated a persistent and adaptive adversary. METR’s monitoring and response processes were able to detect and contain this activity, but the episode served as a further wake-up call for the organisation.

Immediate Security Improvements and Lessons Learned

In response to these incidents, METR undertook several measures to improve its security posture. The organisation enhanced its infrastructure, reviewed protocols, and engaged external security experts for investigation and remediation. They also hired a dedicated security lead and committed to expanding their security team.

The key lessons highlighted by METR’s experience include:

  • Secrets such as API keys should never be stored or used on publicly accessible systems without strict access controls.
  • Authentication systems must be robust against fail-open failures, with regular audits to check for accidental exposure.
  • Spend limits and automated usage alerts are critical to detect and contain abuse quickly.
  • Proactive monitoring for abnormal activity, even in high-usage environments, is essential.

Why the METR API Key Theft Matters

This incident is a stark reminder that even well-intentioned research organisations can fall victim to sophisticated attacks if cloud assets and credentials are not carefully managed. The METR API key theft shows how quickly attackers can exploit simple misconfigurations to cause substantial operational impact. For organisations handling AI models, research data or offering cloud-based services, the stakes are especially high due to the scale and cost of resources involved.

What Organisations Should Do

Organisations should review their secrets management practices, ensure all externally accessible systems have robust authentication, and implement usage-based alerting on all API keys. It is crucial to conduct regular security reviews and to set enforceable spend limits wherever possible. Investing in security leadership and continuous monitoring can help prevent similar incidents.

Originally reported by theregister.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call