Ravie LakshmananSep 01, 2026Cyber Attack / Artificial Intelligence
METR (short for Model Evaluation and Threat Research and pronounced “Meter”), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered “two notable security incidents” where external actors attempted to gain unauthorized access to its systems.
No sensitive information is believed to have been accessed as a result of these incidents, it said, adding that a version of its findings was shared with AI companies it works with prior to public disclosure. The attacks have not been attributed to any known threat actor or group, nor did they involve AI agents breaking into its evaluations.
“In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” METR said. “In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.”
The March Incident
According to METR, one of its researchers with no sensitive access is said to have used agents running on a personal EC2 instance that was intentionally made publicly accessible behind Google authentication. The instance contained an API key for METR’s general-access (public models) account.
However, the “vibe-coded app” suffered from a “fail-open vulnerability” that silently disabled authentication, causing the agent orchestration dashboard to be exposed to the public internet for several days.
“From our analysis, we suspect that the attacker found the instance by looking through recently-registered websites (e.g., in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,” METR explained.
Once the system was identified, the threat actor prompted an agent directly to reveal its model provider API key, added an SSH key for persistent access, and used the stolen credentials to consume a significant amount of API credits on publicly-available models over a period of three weeks.
METR said the accrued credits would have racked up approximately $600,000 in bills had it not been provided to the non-profit for free by the model provider. It did not name the AI company.
It also noted that the illicit usage was not immediately caught because it runs large-scale evaluations and experiments that typically consume a high volume of tokens and the fact that there were no caps on token spend. Following the incident, METR said it has updated its security policies around putting METR credentials or data on non-METR infrastructure or devices, improved monitoring, and added spend alerts to keys where possible.
The May Incident
The second attack observed in May 2026 has been described as a “sustained external attack campaign” orchestrated by a likely financially motivated threat actor to obtain unlawful access to frontier AI models.
“We observed the attackers systematically probing our publicly accessible infrastructure, with heavy use of agents to automate vulnerability discovery, including by credential stuffing authentication providers, attempting OAuth token grants, scanning newly deployed services, and attempting to phish staff,” METR said.
Around the same time, the research entity said it inadvertently exposed a read-only SQL query mechanism built into its public transcript viewer. Although the queries were scoped to public data by default, a bug in the component could have been exploited to access unpublished evaluation data.
In addition, the database “accidentally included” sensitive model data, despite the fact that it was supposed to contain only data from non-sensitive models. METR said it became aware of the issue only after an independent security researcher discovered and reported it, resulting in the API being taken offline.
“The attackers had probed this endpoint in passing as part of their broader campaign, but the evidence shows no indication that they discovered the exploit or accessed any non-public data,” METR said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

