TechNewsReel
Live

AI Safety Non-Profit METR Discloses $600,000 API Credit Theft

Security lapses at the research organization led to a massive unauthorized drain of AI credits and a vulnerability in a public data viewer.

TechNewsReel Newsroom · September 1, 2026

Model Evaluation and Threat Research (METR), a non-profit dedicated to assessing catastrophic risks in frontier AI, has disclosed two significant security breaches that occurred in early 2026. The incidents underscore the fragility of research-grade infrastructure when handling high-value AI assets.

In March 2026, attackers gained access to an API key for public models, consuming approximately $600,000 in AI credits over a three-week period. According to a security update from METR, the key was stolen from a personal EC2 instance deployed by a researcher. The instance contained a "fail-open" vulnerability that silently disabled authentication, leaving the system exposed to the public internet for several days. METR noted that the "vibe-coded app" was the primary point of failure.

While the scale of the credit consumption was massive, METR suffered no direct financial loss. The organization stated that the $600,000 in credits had been granted to them for free by the model developer. However, the breach revealed a critical monitoring gap: METR's internal dashboards failed to alert the organization to the unauthorized usage in real-time, allowing the drain to continue for weeks.

Infrastructure Risks in AI Safety

METR operates in a high-stakes environment, managing sensitive non-public model access and confidential intellectual property. To mitigate these risks, the organization employs a tiered data sensitivity taxonomy—ranging from "Published" to "Highly sensitive information"—designed to isolate risks based on the level of data access. Despite these structural safeguards, the March incident demonstrates how a single, rapidly deployed research tool can bypass organizational security protocols.

Systemic Vulnerabilities

Beyond the API theft, METR disclosed a second security incident in May 2026. This breach involved a read-only SQL query bug discovered in a public transcript viewer. According to the organization, this vulnerability could have potentially exposed unpublished evaluation data to unauthorized parties, though the impact was distinct from the financial scale of the March credit theft.

Industry Implications

These incidents highlight a recurring tension in AI safety and research: the conflict between the need for rapid, flexible experimentation and the requirement for rigorous security. The use of "vibe-coded" or hastily deployed tools creates dangerous entry points for attackers. Furthermore, the METR case serves as a warning regarding the management of free API credits; without strict spending limits and proactive alerting, massive unauthorized usage can remain undetected until long after the damage is done.

Looking Ahead

METR has not detailed specific changes to its EC2 deployment policies following these events, but the disclosure points to a need for tighter integration between researcher-led tools and central security monitoring. The organization continues to evaluate frontier models, but these breaches suggest that the security of the evaluation infrastructure is as critical as the evaluations themselves.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.