Attacker exploited METR API key, consuming $600,000 in credits over weeks
An attacker stole a METR API key and used approximately $600,000 worth of credits without detection for weeks.
By DoomRadar · Published on DoomRadar .
Why it matters
The incident highlights the risk of prolonged unauthorized access and major financial abuse of cloud AI services.
Related source links
These links were collected with this event. Recorded source dates may reflect when a link was found. Article publication dates are shown only when available from the source. Open the originals for their full context.
- Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks ↗theregister.com · Recorded source date: Sep 1, 2026, 10:17 PM UTC
AI-assisted, source-based analysis. Methodology · Report a correction