AI Model Evaluator METR Hit by Credential Theft, Probing

Summary

The AI model evaluator METR has been targeted by threat actors who stole an API key. This credential theft resulted in the unauthorized consumption of $600,000 worth of public AI model credits for the security nonprofit.

IFF Assessment

FOE

The theft of credentials and subsequent misuse of resources represents a direct attack against a security-focused organization, indicating a negative development for defenders.

Defender Context

This incident highlights the risks associated with API key management and the potential for significant financial losses when these credentials are compromised. Defenders should focus on implementing robust key rotation policies, access controls, and monitoring for anomalous API usage to prevent similar incidents.

Read Full Story →