DEV Community

Cover image for METR Reports Dual Security Incidents Involving API Key Theft and Infrastructure Probing
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

METR Reports Dual Security Incidents Involving API Key Theft and Infrastructure Probing

Summary

METR suffered two security incidents in 2026 involving the theft of an AI API key and a sustained infrastructure probing campaign. Attackers exploited a fail-open vulnerability in a researcher's personal instance to consume $600,000 in model credits over three weeks.

Take Action:

If you or your team run "vibe-coded" or AI-generated apps, be very very careful about putting them on an internet-facing cloud instance and giving them real API keys.
Set spending limits and usage alerts on every API key. Any application can be exploited.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)