<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Attackers Steal METR API Key and Consume AI Credits Worth About $600,000]]></title><description><![CDATA[<p dir="auto">METR (<em>Model Evaluation and Threat Research</em>), a non-profit focused on assessing frontier AI models for long-horizon, agentic task performance, has disclosed two separate security incidents involving unauthorized external access attempts. The organization reports that no sensitive information is believed to have been compromised.</p>
<p dir="auto">In the more significant breach, attackers managed to steal a valid METR API key. This key was subsequently abused to consume AI credits worth approximately <strong>$600,000</strong> before the threat was detected and mitigated.</p>
<ul>
<li>The stolen API key was used to run unauthorized model evaluations.</li>
<li>METR has since revoked the compromised credentials and rotated related access tokens.</li>
<li>The organization is reviewing its logging and monitoring to improve detection of similar abuse.</li>
</ul>
<p dir="auto">The second incident did not involve the theft of credentials but is being treated as a notable attempt to probe METR's infrastructure. Both events have prompted a broader security review of their internal tooling and external integrations.</p>
<p dir="auto">While METR has not confirmed the specific vulnerability exploited, they emphasize that no proprietary research data or evaluation results were accessed. The financial impact is limited to the consumed compute credits, which are a direct cost of running large-scale AI models.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your organization tracking API key usage against abnormal spending spikes, or do you rely on static quotas that might delay detection of similar credential abuse?</p>
]]></description><link>https://xploitlk.com/topic/244/attackers-steal-metr-api-key-and-consume-ai-credits-worth-about-600-000</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:28:00 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/244.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 07 Sep 2026 02:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>