AI Model Evaluator METR Hit by Credential Theft, Probing
Summary
Attackers stole an API key (a credential that grants access to services) from METR, a security nonprofit that evaluates AI models, which allowed them to use $600,000 worth of public AI model credits without authorization. The breach demonstrates how a single compromised credential can lead to significant financial damage by enabling unauthorized consumption of cloud resources.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing
First tracked: September 1, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%