AI-evaluation nonprofit METR disclosed that an attacker exploited a fail-open authentication flaw in a publicly accessible, researcher-operated EC2 application in March 2026. The exposure enabled theft of a public-model inference API key and establishment of SSH persistence; the attacker then consumed roughly $600,000 in AI-model credits over about three weeks. METR said the credits had been provided free by the model provider and that it found no evidence that sensitive information was accessed.
A separate, likely financially motivated campaign in May used automated reconnaissance, credential stuffing, OAuth token-grant attempts, service scanning, and phishing against METR staff and infrastructure. METR also remediated a flaw in a public transcript viewer's read-only SQL functionality that could have exposed unpublished evaluation data, including some sensitive model data, but reported no evidence of exploitation. The organization has tightened credential controls and added monitoring and spend alerts.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
METR published an official post-mortem describing the March API-key theft and the sustained May intrusion campaign. The report disclosed technical details of the exposed agent application and SQL endpoint, as well as containment, investigation, and security-hardening actions.
During the May 2026 campaign, METR disabled nearly all public-facing services and internal access to sensitive data while it determined the scope of the attempted intrusion.
During the May 2026 incident, an independent security researcher reported a flaw in METR's public transcript viewer that could have enabled read access to unpublished evaluation data, including sensitive model data inadvertently present in the database. METR took the affected API offline; it found no evidence that the campaign actors exploited the flaw or accessed non-public data.
In early May 2026, METR became the target of a sustained campaign by likely financially motivated actors seeking unauthorized access to frontier AI models. The activity included agent-assisted vulnerability discovery, credential stuffing, OAuth token-grant attempts, scanning newly deployed services, and phishing attempts against staff.
The March attacker used the stolen credentials for approximately three weeks, consuming inference credits that METR estimated would have cost about $600,000. The credits had been supplied to METR free of charge, and METR said no sensitive information was accessed.
In March 2026, a fail-open authentication defect exposed a METR researcher's publicly accessible EC2-hosted agent dashboard. An attacker prompted an exposed agent to reveal a public-model inference API key and added an SSH key for persistent access.
METR established a public-production environment architecturally separated from internal infrastructure to limit the impact of public-service misconfigurations. It also shut down legacy infrastructure that unnecessarily expanded its attack surface.
Following the March incident, METR updated policies for placing its credentials and data on non-METR infrastructure, improved monitoring, and added API-key spending alerts where available. It also strengthened security review processes and hired a security lead.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcexakep.ru
Open sourcescworld.com
Open sourceitpro.com
Open sourcetheregister.com
Open sourcethehackernews.com
Open sourcemetr.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.