METR hit by network compromise
Incident
Summary
Hide ▲
Show ▼
METR disclosed a March 2026 incident in which attackers stole an API key for public-model inference and consumed a substantial amount of credits, creating unauthorized usage and potential cost exposure. The compromise involved a publicly accessible EC2 instance whose authentication failed open, exposing the orchestration dashboard for days. METR said no sensitive information is believed to have been accessed, but the stolen credentials enabled three weeks of abuse that could have generated about $600,000 in charges.
Related Happenings
METR agent orchestration dashboard fail-open authentication security flaw
Vulnerability
H score32
First: 01.09.2026 12:05
Last: 01.09.2026 12:05
Sources 1
How related:
the "vibe-coded app" suffered from a "fail-open vulnerability" that silently disabled authentication, causing the agent orchestration dashboard to be exposed to the public internet for several days.
About this happening:
A fail-open authentication vulnerability in METR’s agent orchestration dashboard exposed the system to the public internet for several days, creating unauthorized-acce...
METR agent orchestration dashboard fail-open authentication security flaw
VulnerabilityHow related: the "vibe-coded app" suffered from a "fail-open vulnerability" that silently disabled authentication, causing the agent orchestration dashboard to be exposed to the public internet for several days.
About this happening: A fail-open authentication vulnerability in METR’s agent orchestration dashboard exposed the system to the public internet for several days, creating unauthorized-acce...
Hugging Face hit by network compromise
Incident
H score48
First: 27.08.2026 21:36
Last: 27.08.2026 21:36
Sources 1
About this happening:
The Hugging Face breach expanded after attackers used a zero-day in HDF5 handling to extract credentials from production workers, increasing their access inside the en...
Hugging Face hit by network compromise
IncidentAbout this happening: The Hugging Face breach expanded after attackers used a zero-day in HDF5 handling to extract credentials from production workers, increasing their access inside the en...
ReliaQuest hit by network compromise
Incident
H score37
First: 27.08.2026 18:12
Last: 27.08.2026 18:12
Sources 1
About this happening:
ReliaQuest suffered a social-engineering incident on August 22, 2026 that gave an attacker a brief view-only session in its identity dashboard. The attacker used a...
ReliaQuest hit by network compromise
IncidentAbout this happening: ReliaQuest suffered a social-engineering incident on August 22, 2026 that gave an attacker a brief view-only session in its identity dashboard. The attacker used a...
Google hit by network compromise
Incident
H score42
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
Google hit by network compromise
IncidentAbout this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
Timeline
-
01.09.2026 12:05 2 articles · 3h ago
METR discloses stolen API key and sustained probing campaign
Initial DisclosureMETR disclosed that attackers stole an API key for inference on public models in March 2026 and consumed a substantial amount of credits, and that in May 2026 it observed a sustained external attack campaign that used credential stuffing, OAuth token grant attempts, service scanning, and phishing against publicly accessible infrastructure. METR said no sensitive information is believed to have been accessed, shared a version of its findings with AI companies it works with before public disclosure, and after the March compromise updated its security policies, monitoring, and spend alerts. METR also said it inadvertently exposed a read-only SQL query mechanism in its public transcript viewer and took the API offline after an independent security researcher reported the issue.
Show sources
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 — thehackernews.com — 01.09.2026 12:05
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 — thehackernews.com — 01.09.2026 12:05