Attacker stole a METR model API key through an agent dashboard and retained access for weeks
METR disclosed that a fail-open authentication flaw in a public agent dashboard let an attacker prompt an agent to expose a public-model API key, establish SSH persistence and use model credits for roughly three weeks.
- First observed
- Aug 31, 2026, 9:00:00 AM
- Disclosed
- Aug 31, 2026, 9:00:00 AM
- Status
- Resolved
- Confidence
- 98%
- Organization
- METR
- Last reviewed
- Sep 4, 2026
Observed
Facts supported by sources
- METR stated that a fail-open authentication flaw in its public agent dashboard allowed an attacker to instruct an agent to reveal a model API key and add an SSH key for persistence.
- METR reported that the attacker used the compromised credentials for about three weeks and consumed credits valued at approximately 600,000 US dollars, while finding no evidence of access to its most sensitive data categories. The exact March incident date was not disclosed, so this record uses the disclosure date as its timeline anchor.
Assessment
Interpretation, not observation
- This was a conventional security compromise enabled by an insecure agent interface, not evidence that the agent acted independently.
- The stated credit value reflects usage value; METR said those credits were free to the organization.
Impact
Impact
Unauthorized model usage, persistent infrastructure access and potential exposure of data reachable from the affected dashboard.
Response
Response
METR revoked access, stopped and imaged the instance, rotated credentials, wiped the endpoint and informed the affected model provider. It also strengthened reviews, monitoring and spending alerts.