# METR discloses API-key theft and attempted access to evaluation data

_Tuesday, September 1, 2026 at 5:05 AM EDT · Security, AI · Latest · Tier 2 — Notable_

![METR discloses API-key theft and attempted access to evaluation data — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2b-1gQHvYc7ZLc86QFtZ2LoJ7zFalpJtSy_e_laxiM_f4Ftnhuvp5eCJZRSk2NL_0tZAZAl2z1UPYfOBSTbdGOPOZexgt3GkuUqsrZPgFB2F-qG2Ir_c7Ioj6zcJVdWjzBo90HpcObPWan5eID2df6OXyn3F7-LRpdOvO8TfiZSp8L2j89p2UbsDi3zM4/s1700-nu-rw-lo-l85-e365/metr.jpg)

AI safety nonprofit METR disclosed two security incidents involving attempts to access its systems. In March, attackers obtained an API key from a publicly accessible personal EC2 instance after a fail-open authentication flaw exposed an agent dashboard; METR said the credentials were used for three weeks and would have incurred about $600,000 in inference credits.

In May, attackers probed public infrastructure while an exposed read-only SQL mechanism could have allowed access to unpublished evaluation data. METR said it found no indication that non-public data was accessed.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html)

---
Canonical: https://techandbusiness.org/newswire/mkG-K7F4FOPQvDqh92jpEj
Retrieved: 2026-09-01T14:58:18.484Z
Publisher: Tech & Business (techandbusiness.org)
