Security Nonprofit METR Hit by Credential Theft and Probing Attacks
A security nonprofit that evaluates risks in frontier AI models has disclosed two cybersecurity incidents this week, including a breach that exposed an API key and led to the theft of $600,000 in public AI model credits. The attacks highlight the growing threat of credential theft and probing attempts on organizations using advanced technologies.
METR (Model Evaluation and Threat Research) is a security-focused nonprofit that helps assess the risks associated with cutting-edge AI models. In March, attackers stole an API key used for inference on public models, which allowed them to consume a “substantial” number of credits. The attack was particularly concerning because it involved a successful compromise in which an attacker used the stolen credentials for weeks. METR described this incident as a “near miss,” but acknowledged that it was a serious breach.
The API key was used by attackers to establish persistence on a system, and they were able to consume approximately $600,000 in public AI model credits over a period of three weeks. The attack was made possible because an AWS EC2 instance included the API key for METR’s public models account. An investigation revealed that the attacker found the instance by searching through recently registered vibe-coded websites for potentially exposed model provider API keys.
The second incident, which occurred in May, involved probing attacks on publicly accessible infrastructure. Attackers attempted to access internal data via an inadvertently exposed endpoint, but were unsuccessful. METR described this as a “sustained external attack campaign” that was likely motivated by financial gain or a desire for advanced AI models.
Both incidents highlight the importance of robust security measures in organizations using advanced technologies. METR has taken steps to strengthen its defenses, including increasing logging coverage, monitoring for unusual API key usage, and rotating credentials. The organization has also hired a security lead and is planning further security expansions.
The attacks on METR serve as a reminder that even well-resourced organizations can fall victim to credential theft and probing attempts. Organizations using advanced technologies should prioritize robust security measures, including regular threat modeling reviews, secure deployment policies for employees, and improved monitoring and alerting.
In particular, organizations handling sensitive model access or non-public models should take extra precautions to protect their data. This includes implementing strict permission controls, conducting regular vulnerability assessments, and monitoring for unusual API key usage. By taking these steps, organizations can minimize the risk of credential theft and probing attacks on their advanced technologies.
Source: Dark Reading — 2026-09-01