Interestana
Home/News/METR Loses $600,000 in AI Credits After API Key Theft
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

METR Loses $600,000 in AI Credits After API Key Theft

METR Loses $600,000 in AI Credits After API Key Theft

METR, a research non-profit focused on evaluating frontier artificial intelligence models for their capacity to perform long-horizon, agentic tasks, disclosed on May 23, 2024, that it experienced two significant security incidents. These incidents involved external actors attempting to gain unauthorized access to METR's systems. The primary consequence of these breaches was the compromise of a METR API key, which was subsequently exploited by attackers. This exploitation led to the consumption of approximately $600,000 worth of AI credits. METR, pronounced "Meter," stands for Model Evaluation and Threat Research and is dedicated to assessing the safety and capabilities of advanced AI systems. The organization's work involves testing AI models for potential risks, particularly in scenarios requiring sustained, goal-directed behavior. The stolen API key provided attackers with access to cloud computing resources that METR utilized for its research operations. The loss of these credits represents a substantial financial impact on the non-profit, potentially hindering its ongoing research efforts. METR stated that it does not believe any sensitive information was compromised during these incidents. The organization is actively investigating the breaches and has implemented additional security measures to prevent future occurrences. The nature of the "agentic tasks" METR evaluates involves AI systems acting autonomously over extended periods to achieve complex objectives, a capability that requires significant computational resources. The theft highlights the growing security risks associated with the extensive use of cloud-based AI development platforms and the critical importance of securing API keys and other access credentials. METR's mission to evaluate AI models for safety and potential threats underscores the irony of its own systems being targeted. The organization's focus on "frontier" AI models means it is often working with the most advanced and computationally intensive systems available, making the cost of such attacks particularly high. The incident serves as a stark reminder for all organizations utilizing AI development tools and cloud infrastructure to maintain robust cybersecurity practices. The loss of $600,000 in AI credits is a significant setback for a research non-profit, potentially impacting its ability to conduct timely and comprehensive evaluations of emerging AI technologies. METR's commitment to transparency in reporting these incidents is crucial for the broader AI safety community, providing valuable insights into the evolving threat landscape.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next