Summary
METR suffered two security incidents in 2026 involving the theft of an AI API key and a sustained infrastructure probing campaign. Attackers exploited a fail-open vulnerability in a researcher's personal instance to consume $600,000 in model credits over three weeks.
Take Action:
If you or your team run "vibe-coded" or AI-generated apps, be very very careful about putting them on an internet-facing cloud instance and giving them real API keys.
Set spending limits and usage alerts on every API key. Any application can be exploited.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)