Back to News
Cybersecurity

Significant Security Breach at METR: $600,000 in AI Credits Stolen

METR reports a major security breach leading to the theft of API keys and substantial AI credits, highlighting vulnerabilities in AI infrastructures.

METR, a non-profit organization dedicated to evaluating advanced AI models, has reported two significant security breaches wherein attackers successfully stole an API key. This breach resulted in the unauthorized consumption of AI credits valued at approximately $600,000. While METR has indicated that no sensitive information was compromised during these incidents, the financial impact underscores a growing concern regarding the security of AI infrastructures and the potential for similar attacks on other organizations.

For businesses leveraging AI technologies, this incident serves as a stark reminder of the importance of robust cybersecurity measures. Organizations must prioritize the protection of API keys and other critical credentials, as their compromise can lead to substantial financial losses and operational disruptions. This situation emphasizes the necessity for enhanced security protocols and regular audits to safeguard AI resources, ensuring that businesses can harness AI's potential without exposing themselves to significant vulnerabilities in the process. The METR breach highlights the ongoing challenges in securing AI systems and the need for the cybersecurity community to develop more effective strategies to mitigate such risks.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html)*