METR Discloses Two Security Incidents, Says No Sensitive Data Accessed
METR, a nonprofit that evaluates frontier AI models, has disclosed two security incidents from earlier this year affecting its own systems. In March, attackers stole an API key used for inference on public models and consumed a significant amount of credits. In May, attackers systematically probed METR's publicly accessible infrastructure, including an unsuccessful attempt to access internal data through an inadvertently exposed endpoint.
METR said an investigation with external security consultants found no evidence that sensitive information from its most confidential data categories was accessed in either incident, though some sensitive model output data was found to have been inadvertently accessible, without evidence it was actually accessed. The organisation treated both events as near-misses and increased its security investment as a result, building on existing controls that had already contributed to its SOC 2 Type I certification.
METR also noted it has begun an initial scan of its AI model evaluations and currently has no evidence that AI agents used during testing hacked into third-party systems, with a more detailed update promised soon.