$ techbeacon▋
Threats

Hackers Exploit Stolen METR API Key, Waste $600,000 in AI Credits

Hackers Exploit Stolen METR API Key, Waste $600,000 in AI Credits

Security researchers have confirmed that a group of attackers accessed a METR API key and used it for roughly three weeks, depleting the account of model credits valued at about $600,000. The breach, first reported by Infosecurity Magazine, highlights the financial risk that can arise when cloud‑based AI services are left unsecured.

According to the investigation, the stolen key granted the intruders unrestricted access to METR's suite of generative‑AI models. Over the course of the attack, the perpetrators submitted thousands of requests, rapidly consuming the prepaid credit pool. The total cost, calculated from METR's published pricing, reached six hundred thousand dollars before the anomaly was detected.

METR, a provider of AI‑as‑a‑service platforms, sells access to its models through a credit system that customers purchase in advance. Each API call deducts a portion of these credits based on the computational resources required. While this model offers flexibility for developers, it also creates a tempting target for malicious actors who can generate large volumes of requests at a low marginal cost.

The incident underscores a broader trend in which threat actors focus on abusing cloud‑based AI services rather than traditional data theft. Similar episodes have been documented with other providers, where compromised API keys were leveraged to run costly workloads, generate spam, or produce deep‑fake content. Experts say the rapid adoption of AI tools has outpaced the development of robust key‑management practices, leaving many organizations vulnerable.

METR has responded by revoking the compromised key, initiating a forensic review, and offering affected customers credit reimbursements where applicable. The company also announced plans to roll out additional safeguards, including mandatory rotation of API secrets, enhanced usage‑monitoring alerts, and optional multi‑factor authentication for API access. Industry analysts suggest that the episode will accelerate demand for tighter credential controls and real‑time anomaly detection across AI service platforms.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related