AI Incidents
Back to incident register
Source reviewedSecurity breachHigh

Attacker stole a METR model API key through an agent dashboard and retained access for weeks

METR disclosed that a fail-open authentication flaw in a public agent dashboard let an attacker prompt an agent to expose a public-model API key, establish SSH persistence and use model credits for roughly three weeks.

First observed
Aug 31, 2026, 9:00:00 AM
Disclosed
Aug 31, 2026, 9:00:00 AM
Status
Resolved
Confidence
98%
Organization
METR
Last reviewed
Sep 4, 2026

Observed

Facts supported by sources

  • METR stated that a fail-open authentication flaw in its public agent dashboard allowed an attacker to instruct an agent to reveal a model API key and add an SSH key for persistence.
  • METR reported that the attacker used the compromised credentials for about three weeks and consumed credits valued at approximately 600,000 US dollars, while finding no evidence of access to its most sensitive data categories. The exact March incident date was not disclosed, so this record uses the disclosure date as its timeline anchor.

Assessment

Interpretation, not observation

  • This was a conventional security compromise enabled by an insecure agent interface, not evidence that the agent acted independently.
  • The stated credit value reflects usage value; METR said those credits were free to the organization.

Impact

Impact

Unauthorized model usage, persistent infrastructure access and potential exposure of data reachable from the affected dashboard.

Response

Response

METR revoked access, stopped and imaged the instance, rotated credentials, wiped the endpoint and informed the affected model provider. It also strengthened reviews, monitoring and spending alerts.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.