The AI Post
Agents & CodingOpen ModelsEnterpriseFundraisingGenerative MediaGovernanceInferenceInfrastructureLegal & SafetySector Impact
← Front Page Security · METR

Attacker racks up $600,000 in tokens on stolen AI key

An attacker found a weak, self-built AI agent app on an employee's personal server at the AI evaluator METR and used its API key for three weeks, The Hacker News reported.

An attacker compromised an employee's personal cloud server at the AI evaluator METR, The Hacker News reported. Using a stolen model-provider API key, the attacker ran up about $600,000 in token costs over three weeks.

The employee had been running what the outlet called a "vibe-coded" agentic app with weak authentication on a personal EC2 instance, according to The Hacker News. It said the attacker bypassed that authentication and prompted the agent into handing over its model provider's API key directly.

Token volume alone did not trigger any alert, and METR's internal dashboard did not track rate-limited requests at all, the outlet said. It cited the episode as evidence that visibility, not blocking, is the first step in securing AI agents.

The report frames the incident as an argument for zero-trust security: build an inventory of what agents exist and what they can reach before adding enforcement controls. It did not say whether METR disclosed the breach publicly at the time it happened.

Sources 2 sources

  1. Source The Hacker News
  2. Source TheHackersNews