Hackers Exploit Stolen METR API Key, Waste $600,000 in AI Credits
Security researchers have confirmed that a group of attackers accessed a METR API key and used it for roughly three weeks, depleting the account of model credits valued at about $600,000. The breach, first reported by Infosecurity Magazine, highlights the financial risk that can arise when cloud‑based AI services are left unsecured.
According to the investigation, the stolen key granted the intruders unrestricted access to METR's suite of generative‑AI models. Over the course of the attack, the perpetrators submitted thousands of requests, rapidly consuming the prepaid credit pool. The total cost, calculated from METR's published pricing, reached six hundred thousand dollars before the anomaly was detected.
METR, a provider of AI‑as‑a‑service platforms, sells access to its models through a credit system that customers purchase in advance. Each API call deducts a portion of these credits based on the computational resources required. While this model offers flexibility for developers, it also creates a tempting target for malicious actors who can generate large volumes of requests at a low marginal cost.
The incident underscores a broader trend in which threat actors focus on abusing cloud‑based AI services rather than traditional data theft. Similar episodes have been documented with other providers, where compromised API keys were leveraged to run costly workloads, generate spam, or produce deep‑fake content. Experts say the rapid adoption of AI tools has outpaced the development of robust key‑management practices, leaving many organizations vulnerable.
METR has responded by revoking the compromised key, initiating a forensic review, and offering affected customers credit reimbursements where applicable. The company also announced plans to roll out additional safeguards, including mandatory rotation of API secrets, enhanced usage‑monitoring alerts, and optional multi‑factor authentication for API access. Industry analysts suggest that the episode will accelerate demand for tighter credential controls and real‑time anomaly detection across AI service platforms.
Comments (0)
Be the first to comment.
Join the discussion