Skip to content
theregister·

🔒METR API Key Stolen, $600k in Free Credits Used

How a vibe-coded app's bug led to a $600k API credit spree

TL;DR

An attacker exploited a vibe-coded app's bug to steal METR's API key, using $600k worth of free credits over three weeks. The incident highlights the importance of robust security measures for API keys and public infrastructure.

An attacker exploited a bug in a vibe-coded app to steal an API key from METR, using $600,000 worth of free credits over three weeks. The incident underscores the need for developers to secure API keys and public infrastructure. METR improved its security protocols and hired a security lead in response. The attacker found the API key by searching for recently-registered websites with high-signal keywords related to LLMs or agents. The model testing operation regularly runs evaluations that use a lot of tokens, making the high usage look ordinary. The attacker added an SSH key to maintain persistent access.

METR API Key Stolen, $600k in Free Credits Used — theregister

Key Points

1

An attacker stole an API key from METR, using $600k worth of free credits over three weeks.

2

The attacker found the API key by searching for recently-registered websites with high-signal keywords related to LLMs or agents.

3

The model testing operation regularly runs evaluations that use a lot of tokens, making the high usage look ordinary.

4

METR improved its security protocols and hired a security lead in response to the incident.

5

An independent bug hunter discovered a vulnerability in METR's public transcript viewer and reported it to METR.

Why It Matters

If you're managing API keys or public infrastructure, this incident highlights the importance of robust security measures. The attacker used a vibe-coded app's bug to gain access, and the high usage of tokens made it look ordinary. METR's response shows the need for continuous security improvements.

api securitycloud securityincident responsesecurity protocolsapi keys

Frequently Asked Questions

Why does this matter?

If you're managing API keys or public infrastructure, this incident highlights the importance of robust security measures. The attacker used a vibe-coded app's bug to gain access, and the high usage of tokens made it look ordinary. METR's response shows the need for continuous security improvements.

What happened?

An attacker exploited a vibe-coded app's bug to steal METR's API key, using $600k worth of free credits over three weeks. The incident highlights the importance of robust security measures for API keys and public infrastructure.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,436 builders reading daily.

Also get