<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/metr-lost-a-600k-api-key-to-attackers-for-three-weeks-before-anyone-noticed-a1dhy4v2h" -->

---
title: METR lost a $600K API key to attackers for three weeks...
description: METR, an AI safety research organization, disclosed that an attacker stole an API key and racked up roughly $600,000 in model usage over three weeks before...
canonical: https://daily.dev/posts/metr-lost-a-600k-api-key-to-attackers-for-three-weeks-before-anyone-noticed-a1dhy4v2h
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: METR lost a $600K API key to attackers for three weeks before anyone noticed | daily.dev
og:description: METR, an AI safety research organization, disclosed that an attacker stole an API key and racked up roughly $600,000 in model usage over three weeks before...
og:url: https://daily.dev/posts/metr-lost-a-600k-api-key-to-attackers-for-three-weeks-before-anyone-noticed-a1dhy4v2h
og:image: https://api.daily.dev/og/posts/a1Dhy4v2h.png
og:image:alt: METR lost a $600K API key to attackers for three weeks before anyone noticed
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# METR lost a $600K API key to attackers for three weeks before anyone noticed

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

METR, an AI safety research organization, disclosed that an attacker stole an API key and racked up roughly $600,000 in model usage over three weeks before anyone noticed. The key leaked from a vibe-coded internal dashboard on a researcher's personal EC2 instance whose Google auth failed open, letting anyone who found the endpoint (likely via certificate-transparency logs) prompt the agent behind it into revealing its credentials. Because the credits were free from a model provider with no spending cap, there was no invoice to trigger an alert, and the attacker's usage blended into METR's normally high token volume. The lesson: spend limits and usage alerts on API keys matter even when the credits cost nothing.

## Content

METR, an AI safety research organization, disclosed a security incident in which an attacker stole an API key and used roughly $600,000 worth of model credits over several weeks without anyone catching it.

The key was exposed through a vibe-coded internal dashboard running on a researcher's personal EC2 instance. The dashboard had a broken Google authentication setup that failed open, meaning anyone who hit the right endpoint got in. Attackers likely found the service through certificate-transparency logs, then directly prompted the agent running behind it to hand over its API credentials.

Once they had the key, they used it for three weeks. The reason nobody noticed: the credits had been provided to METR for free by a model provider, so there was no bill to trigger an alert. The free-credit keys also had no spending cap. On top of that, METR routinely generates large token volumes for its evaluations, so the attacker's usage blended into normal traffic.

A paying customer would have seen a very large invoice. METR saw nothing until they looked.

The incident is a straightforward lesson in credential hygiene - even organizations whose entire focus is AI safety apparently weren't monitoring API key usage closely enough to catch three weeks of abuse. Spend limits and usage alerts on API keys aren't optional, even when the credits are free.

## Questions this post answers

### How did attackers steal METR's API key and use $600,000 in credits without being detected?

Attackers found a vibe-coded internal dashboard running on a researcher's personal EC2 instance whose Google authentication failed open, letting anyone hitting the right endpoint in, likely discovered via certificate-transparency logs. They then prompted the agent behind the dashboard into handing over its API credentials and used the stolen key for three weeks, racking up about $600,000 in model usage. Detection failed because the credits were free from a model provider with no spending cap, so no invoice ever triggered an alert, and the traffic blended into METR's normally high token volume from evaluations.

_Teams securing internal AI tooling can follow real-world credential leak incidents like this on daily.dev._

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#ai-safety](https://daily.dev/tags/ai-safety), [#aws-ec2](https://daily.dev/tags/aws-ec2)

[View this post on daily.dev](https://daily.dev/posts/metr-lost-a-600k-api-key-to-attackers-for-three-weeks-before-anyone-noticed-a1dhy4v2h)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"METR lost a $600K API key to attackers for three weeks before anyone noticed","url":"https://daily.dev/posts/metr-lost-a-600k-api-key-to-attackers-for-three-weeks-before-anyone-noticed-a1dhy4v2h","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/metr-lost-a-600k-api-key-to-attackers-for-three-weeks-before-anyone-noticed-a1dhy4v2h"},"datePublished":"2026-09-02T02:57:24.555Z","dateModified":"2026-09-02T02:58:02.611Z","description":"METR, an AI safety research organization, disclosed that an attacker stole an API key and racked up roughly $600,000 in model usage over three weeks before...","image":"https://pbs.twimg.com/media/HRLea0kbcAAlCgB.png","thumbnailUrl":"https://pbs.twimg.com/media/HRLea0kbcAAlCgB.png","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/metr-lost-a-600k-api-key-to-attackers-for-three-weeks-before-anyone-noticed-a1dhy4v2h","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,ai-safety,aws-ec2","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"METR lost a $600K API key to attackers for three weeks before anyone noticed"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/metr-lost-a-600k-api-key-to-attackers-for-three-weeks-before-anyone-noticed-a1dhy4v2h#faq","mainEntity":[{"@type":"Question","name":"How did attackers steal METR's API key and use $600,000 in credits without being detected?","acceptedAnswer":{"@type":"Answer","text":"Attackers found a vibe-coded internal dashboard running on a researcher's personal EC2 instance whose Google authentication failed open, letting anyone hitting the right endpoint in, likely discovered via certificate-transparency logs. They then prompted the agent behind the dashboard into handing over its API credentials and used the stolen key for three weeks, racking up about $600,000 in model usage. Detection failed because the credits were free from a model provider with no spending cap, so no invoice ever triggered an alert, and the traffic blended into METR's normally high token volume from evaluations. Teams securing internal AI tooling can follow real-world credential leak incidents like this on daily.dev."}}]}
```

