In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
September 1, 2026
A security nonprofit that helps evaluate risks in frontier AI models disclosed two cybersecurity incidents this week, including a breach that exposed an API key and a separate vulnerability that could have exposed nonpublic evaluation data.
METR (Model Evaluation and Threat Research) disclosed two security incidents on Aug. 31 in which it was targeted by cyberattackers. In March of this year, attackers stole an API key used for inference on public models and consumed what METR described in a blog post as a "substantial" number of credits. In May, the company saw attackers probe publicly accessible infrastructure, including "an unsuccessful attempt to access internal data via an inadvertently exposed endpoint."
Although METR described both incidents as "near misses," the March event involved a successful compromise in which an attacker used the API key to establish persistence on a system, and used the stolen credentials for weeks. In any case, METR said it increased its security investment in response.






