Threat Intelligence

AI Research Nonprofit METR Hit by API Key Theft, Racks Up $600,000 in Unauthorised AI Usage

The Hacker News · 1 Sept 2026
Key Takeaway Treat API keys like passwords: store them securely, rotate them regularly, restrict their permissions and spending limits, and monitor usage for unexpected spikes.

METR, a nonprofit that evaluates advanced AI models for their potential to carry out complex, autonomous tasks, has disclosed two separate security incidents involving unauthorised access attempts against its systems. In one incident, attackers managed to steal an API key and used it to run up approximately $600,000 in AI service credits before the activity was detected and stopped.

While METR stated that no sensitive information is believed to have been exposed, the incident highlights a growing risk for organisations that rely on API-based access to cloud and AI services: a single leaked or poorly protected credential can be exploited quickly and at significant cost. Attackers who obtain valid API keys can often operate undetected for a period, since their activity may resemble legitimate usage rather than an obvious intrusion.

This case is a reminder that credential theft doesn't only lead to data breaches — it can also result in direct financial losses through abuse of paid services. For small and medium businesses increasingly using AI tools and cloud APIs, protecting these keys with the same rigour as passwords and financial credentials is essential.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.