A vibe-coded app with a built in fail-open vulnerability allowed attackers to hijack an AI model API at research non-profit METR and use $600,000 worth of credits before they were caught.
In a security update on 31 August, the organisation admitted one of its researchers running AI agents on a personal EC2 instance had accidentally exposed the API key for its general access AI models account in March.
METR said it had free access to the models in question so did not notice the activity, and added frequent large evaluations and early model access “means we are very acclimated to getting lots of weird rate limit and API errors, many of which are spurious and don’t actually reflect high usage.”
While the incident’s impact appears minor for the AI model evaluator, it is the latest to highlight security failings during AI research following OpenAI’s admission that one of its models had been able to access the internet and breach Hugging Face during testing. What happened?
Get the full story: Subscribe for free #
Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.
[Subscribe now](https://www.thestack.technology/membership/)
Already a member? [Sign in](https://www.thestack.technology/signin/)