Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
Summary
An attacker stole an API key for METR, a cloud provider, and used approximately $600,000 worth of free credits before the theft was discovered. The attacker was able to exploit the free credits provided to METR by the model provider, meaning a legitimate customer would have incurred significant costs.
IFF Assessment
This article highlights a successful unauthorized access and resource abuse incident, indicating a win for attackers and a loss for defenders.
Defender Context
This incident underscores the critical importance of securing API keys, especially those that grant access to potentially costly cloud resources. Defenders should implement strict access controls, monitor API key usage for anomalous activity, and consider time-limited or usage-capped keys to mitigate the impact of compromised credentials.