METR Loses $600K in AI Credits After Fail-Open Auth Exposes API Keys and SSH Access
AI safety evaluator METR suffered two separate security incidents in which attackers exploited a fail-open authentication flaw in a researcher's personal AWS EC2-hosted dashboard. An attacker manipulated an AI agent into revealing its model provider API key, then established SSH persistence and spent roughly $600,000 in unauthorized inference credits over three weeks. The stolen key lacked usage caps, source restrictions, or anomaly alerts, allowing the abuse to blend in with normal evaluation traffic. In a second, unrelated incident, a public SQL query mechanism in METR's transcript viewer was found to expose a path to unreleased evaluation data, though no confirmed unauthorized access to private data occurred. METR has since shut down the affected API and recommended that teams enforce fail-closed authentication, avoid mixing corporate credentials with personal cloud environments, and apply least-privilege, short-lived keys with usage monitoring.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in