METR disclosed two security incidents from earlier this year. The nonprofit tests AI models for dangerous capabilities. In March 2026 an attacker stole an API key and burned about $600,000 of model credits over three weeks. The key sat on a researcher's personal cloud server, left public behind Google sign-in. A quickly built app had a bug that switched authentication off entirely. The attacker prompted an agent to reveal the key, then added an SSH key for lasting access. METR suspects the attacker hunted newly registered sites for exposed keys. Nobody noticed because heavy token use is normal there and the credits were free. In May, attackers probed METR's public systems using automated tools, phishing and credential stuffing. A bug in METR's public transcript viewer also exposed unpublished evaluation data.
What changed
METR had no way to set a spending limit on the stolen key, and no dedicated security lead.
- ~$600,000 of credits consumed
- 3 weeks of undetected use
- 2 incidents: March and May 2026
Sources