← Back to Feed

AI Model Evaluator METR Hit by Credential Theft, Probing

September 1, 2026 · Dark Reading · Severity: MEDIUM

In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.

Key Takeaways

  • Credential theft of API keys can lead to massive financial losses.
  • Organizations should monitor API usage for anomalies to detect breaches.
  • AI model evaluators are attractive targets for attackers seeking resources.
☕ Buy a Coffee