← DOOMRADAR

cyber · Published brief

Attacker exploited METR API key, consuming $600,000 in credits over weeks

An attacker stole a METR API key and used approximately $600,000 worth of credits without detection for weeks.

By DoomRadar · Published on DoomRadar .

Why it matters

The incident highlights the risk of prolonged unauthorized access and major financial abuse of cloud AI services.

Related source links

These links were collected with this event. Recorded source dates may reflect when a link was found. Article publication dates are shown only when available from the source. Open the originals for their full context.

  1. Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks ↗theregister.com · Recorded source date: Sep 1, 2026, 10:17 PM UTC

AI-assisted, source-based analysis. Methodology · Report a correction