cd /news/ai-safety/how-a-vibe-coded-app-let-hackers-use… · home topics ai-safety article
[ARTICLE · art-117907] src=thestack.technology ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

How a vibe-coded app let hackers use $600k worth of AI tokens at METR

A vibe-coded app with a fail-open vulnerability allowed attackers to hijack an AI model API at research non-profit METR and use $600,000 worth of credits before being caught, according to a security update on 31 August. METR admitted a researcher running AI agents on a personal EC2 instance had accidentally exposed the API key for its general access AI models account in March, and the organization did not notice the activity because it had free access to the models and was accustomed to frequent API errors.

read1 min views2 publishedSep 1, 2026
How a vibe-coded app let hackers use $600k worth of AI tokens at METR
Image: Thestack (auto-discovered)

A vibe-coded app with a built in fail-open vulnerability allowed attackers to hijack an AI model API at research non-profit METR and use $600,000 worth of credits before they were caught.

In a security update on 31 August, the organisation admitted one of its researchers running AI agents on a personal EC2 instance had accidentally exposed the API key for its general access AI models account in March.

METR said it had free access to the models in question so did not notice the activity, and added frequent large evaluations and early model access “means we are very acclimated to getting lots of weird rate limit and API errors, many of which are spurious and don’t actually reflect high usage.”

While the incident’s impact appears minor for the AI model evaluator, it is the latest to highlight security failings during AI research following OpenAI’s admission that one of its models had been able to access the internet and breach Hugging Face during testing. What happened?

Get the full story: Subscribe for free #

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

[Subscribe now](https://www.thestack.technology/membership/)

Already a member? [Sign in](https://www.thestack.technology/signin/)
── more in #ai-safety 4 stories · sorted by recency
── more on @metr 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/how-a-vibe-coded-app…] indexed:0 read:1min 2026-09-01 ·