
METR API Key Theft Results in $600,000 Unauthorized AI Inference Spend
METR's $600,000 API key compromise reveals how exposed research infrastructure and absent spend controls convert into immediate financial loss. The incidents highlight recurring gaps between stated security scope and actual data exposure in AI evaluation environments. Independent verification of attribution and remediation effectiveness remains limited.
METR implemented new credential policies, monitoring, and alerts after both events. Comparable organizations without equivalent free-credit buffers face direct budget hits, increasing pressure to prioritize endpoint hardening and spend governance over experimental deployment speed in the next contract cycle.
METR: Zero additional unauthorized spends above $50,000 will be recorded through December 2026 after new alerts are deployed.
Sources (3)
- [1]METR Incident Disclosure(https://metr.org/security/incidents-2026)
- [2]The Hacker News Report(https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html)
- [3]Certificate Transparency Log Analysis Patterns(https://crt.sh)