AI Model Evaluator METR Hit by Credential Theft, Probing
Attackers stole an API key from AI-evaluation nonprofit METR and burned through $600K in model credits, spotlighting the financial risk of unsecured AI-service credentials.
Summary written by editorial AI · Source link below
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
Editorial Analysis
As enterprises scale AI adoption, a single leaked API key can generate six-figure cloud costs within hours — a risk most budgeting models don't yet capture.
Enforce spend-limit policies and anomaly alerts on all AI-platform API keys, and store them exclusively in a secrets vault.
A stolen AI-service credential caused $600K in charges overnight — AI cost controls are now a security imperative.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.
More from the AI Security Desk
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident2d
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel3d
- Using a VM to Contain an AI Agent3d
- Companies Have 6 Months to Prepare for Automated Attacks3d
- [NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen3d