Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

Summary

An attacker stole an API key for METR, a cloud provider, and used approximately $600,000 worth of free credits before the theft was discovered. The attacker was able to exploit the free credits provided to METR by the model provider, meaning a legitimate customer would have incurred significant costs.

IFF Assessment

FOE

This article highlights a successful unauthorized access and resource abuse incident, indicating a win for attackers and a loss for defenders.

Defender Context

This incident underscores the critical importance of securing API keys, especially those that grant access to potentially costly cloud resources. Defenders should implement strict access controls, monitor API key usage for anomalous activity, and consider time-limited or usage-capped keys to mitigate the impact of compromised credentials.

Read Full Story →