METR (quick for Mannequin Analysis and Risk Analysis and pronounced “Meter”), a analysis non-profit that evaluates frontier synthetic intelligence (AI) fashions for his or her means to hold out long-horizon, agentic duties, disclosed that it suffered “two notable safety incidents” the place exterior actors tried to realize unauthorized entry to its techniques.
No delicate data is believed to have been accessed because of these incidents, it stated, including {that a} model of its findings was shared with AI firms it really works with previous to public disclosure. The assaults haven’t been attributed to any recognized risk actor or group, nor did they contain AI brokers breaking into its evaluations.
“In March 2026, attackers stole an API key for inference on public fashions and consumed a considerable quantity of credit,” METR said. “In Might 2026, we noticed attackers systematically probing our publicly accessible infrastructure, together with an unsuccessful try to entry inner knowledge through an inadvertently uncovered endpoint.”
The March Incident
In keeping with METR, one in all its researchers with no delicate entry is alleged to have used brokers working on a private EC2 occasion that was deliberately made publicly accessible behind Google authentication. The occasion contained an API key for METR’s general-access (public fashions) account.
Nevertheless, the “vibe-coded app” suffered from a “fail-open vulnerability” that silently disabled authentication, inflicting the agent orchestration dashboard to be uncovered to the general public web for a number of days.
“From our evaluation, we suspect that the attacker discovered the occasion by wanting via recently-registered web sites (e.g., in certificates transparency lists) to search out vibe-coded websites with high-signal key phrases referring to LLMs or brokers, for functions of harvesting doubtlessly uncovered mannequin supplier API keys,” METR defined.
As soon as the system was recognized, the risk actor prompted an agent on to reveal its mannequin supplier API key, added an SSH key for persistent entry, and used the stolen credentials to devour a major quantity of API credit on publicly-available fashions over a interval of three weeks.
METR stated the accrued credit would have racked up roughly $600,000 in payments had it not been supplied to the non-profit without cost by the mannequin supplier. It didn’t title the AI firm.
It additionally famous that the illicit utilization was not instantly caught as a result of it runs large-scale evaluations and experiments that sometimes devour a excessive quantity of tokens and the actual fact that there have been no caps on token spend. Following the incident, METR stated it has up to date its safety insurance policies round placing METR credentials or knowledge on non-METR infrastructure or gadgets, improved monitoring, and added spend alerts to keys the place potential.
The Might Incident
The second assault noticed in Might 2026 has been described as a “sustained exterior assault marketing campaign” orchestrated by a possible financially motivated risk actor to acquire illegal entry to frontier AI fashions.
“We noticed the attackers systematically probing our publicly accessible infrastructure, with heavy use of brokers to automate vulnerability discovery, together with by credential stuffing authentication suppliers, trying OAuth token grants, scanning newly deployed providers, and trying to phish workers,” METR stated.
Across the identical time, the analysis entity stated it inadvertently uncovered a read-only SQL question mechanism constructed into its public transcript viewer. Though the queries have been scoped to public knowledge by default, a bug within the element might have been exploited to entry unpublished analysis knowledge.
As well as, the database “unintentionally included” delicate mannequin knowledge, even supposing it was imagined to include solely knowledge from non-sensitive fashions. METR stated it grew to become conscious of the problem solely after an unbiased safety researcher found and reported it, ensuing within the API being taken offline.
“The attackers had probed this endpoint in passing as a part of their broader marketing campaign, however the proof reveals no indication that they found the exploit or accessed any personal knowledge,” METR stated.
