← Home
CYBERSECURITY

AI Model Evaluator METR Hit by Credential Theft, Probing

September 8, 2026 Priya Nair

The company has since revoked the compromised key, strengthened access controls

METR, an AI model evaluation platform, confirmed a security breach in which threat actors stole an API key, leading to unauthorized consumption of cloud resources valued at approximately $600,000. The incident was detected during routine monitoring, prompting an immediate investigation into the scope and origin of the compromise. METR has not disclosed the exact timing of the breach but stated that the stolen credential was used to access internal systems linked to model testing environments. The breach occurred when attackers gained access to a valid API key, which allowed them to initiate extensive computational workloads without authorization. These workloads consumed significant cloud infrastructure, resulting in substantial financial exposure before the activity was identified and halted. METR emphasized that no customer data or proprietary model outputs were accessed or exfiltrated during the incident.

The company has since revoked the compromised key, strengthened access controls, and engaged third-party forensic experts to analyze the attack vector. How the API Key Was Exploited Investigators found that the stolen API key lacked sufficient restrictions on usage scope and duration, enabling attackers to run prolonged evaluation jobs across multiple model configurations. The exploit leveraged METR’s automated testing pipeline, which is designed to scale dynamically based on demand. This design, while efficient for legitimate use, created an opportunity for abuse when credentials were exposed. METR noted that the key had been stored in a development environment with weaker security protocols than production systems. What Steps Is METR Taking to Prevent Recurrence? In response, METR has implemented mandatory rotation of all API keys, introduced usage anomaly detection, and enforced stricter role-based access controls across its infrastructure.

The company is also reviewing its credential management policies, particularly for non-production environments

The company is also reviewing its credential management policies, particularly for non-production environments, to reduce the risk of similar exposures. METR stated it will require multi-factor authentication for all administrative and service accounts by the end of the quarter. Affected cloud providers have been notified, and METR is working with them to assess potential reimbursement for unauthorized consumption. Frequently Asked Questions Was any customer data compromised in the breach? No, METR confirmed that the incident did not involve access to customer data, model inputs, or outputs. The unauthorized activity was limited to computational resource consumption within isolated evaluation environments. How did METR discover the unauthorized activity? The breach was identified through anomalous usage spikes detected by internal monitoring systems, which triggered alerts for unexpected cloud consumption patterns. What is the estimated financial impact of the incident?

The unauthorized consumption of cloud resources resulted in an estimated cost of $600,000, based on usage metrics and provider billing data collected during the investigation.

Read full article on Tech Site News →