METR Reports Two Security Incidents, Including Stolen API Key Used for Public Model Credits
Original titleUpdate on Security at METR
AISummary
METR disclosed two 2026 security incidents in which external attackers attempted unauthorized access, with no evidence of AI agents hacking third parties during its evaluations.
In March, attackers stole an API key from a researcher's personal instance and consumed credits on public models that were worth about $600,000 but were granted to METR for free.
METR says it found no evidence that sensitive information was accessed in either incident.
Source: METR Blog · metr.orgPublished · added here