negativeSYS.SOURCE: The Hacker News• 2026-09-01T14:35:30+05:30
METR API Key Compromise Leads to $600K AI Credit Depletion
Attackers exploited a vulnerability in METR's infrastructure to steal an API key, leading to unauthorized consumption of AI credits worth approximately $600,000. The incident involved two separate security breaches in March and May 2026, with no sensitive data compromised but significant financial impact.
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its systems.
No sensitive information is believed to
*** END OF TRANSMISSION ***