The record
Written from the 1 report below. Nothing here is unsourced.
- METR, a non-profit that evaluates frontier AI models, disclosed two security incidents in 2026 in which outside actors tried to gain unauthorized access to its systems.
- In March 2026, attackers stole an API key by exploiting a vulnerability that silently disabled authentication on a publicly accessible server and consumed AI model credits worth about $600,000 over three weeks.
- In May 2026, attackers systematically probed METR's public infrastructure, using automated agents for vulnerability discovery, credential stuffing, and phishing attempts against staff.
- METR also inadvertently exposed a read-only SQL query mechanism that could have allowed access to unpublished evaluation data, and the flaw was found and reported by an independent security researcher.
- No sensitive information is believed to have been accessed in either incident, and the attacks have not been attributed to any known threat actor.
What to watch next
- Whether METR names the AI model provider that covered the $600,000 in credits.
- Whether attribution of either attack to a specific threat actor emerges later.
- Whether the exposed endpoint led to any non-public data access as further evidence is reviewed.
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
METR
2 quotes · 1 outlet
“In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits”
In the article
…findings was shared with AI companies it works with prior to public disclosure. The attacks have not been attributed to any known threat actor or group, nor did they involve AI agents breaking into its evaluations. " In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits ," METR said. "In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint." The…
“In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.”
In the article
…threat actor or group, nor did they involve AI agents breaking into its evaluations. "In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits," METR said. " In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint. " The March Incident According to METR, one of its researchers with no sensitive access is said to have used agents running on a personal EC2 instance that was intentionally made publicly accessible behind Google…
Coverage1
All filed from India
Named United States · Amazon Web Services · METR · Google
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
