Somebody Stole METR's AI Snacks and Ran Up a $600K Tab, No Cap 😭🐑

Somebody Stole METR's AI Snacks and Ran Up a $600K Tab, No Cap 😭🐑

Okay BESTIE, I am literally vibrating with secondhand embarrassment right now. Like, I had my oat milk latte, I was having a MOMENT, and then this news dropped and absolutely ruined my whole digital vibe. We need to talk about METR.

So METR (it's pronounced "Meter," which, okay, cute, whatever) is this fancy AI research non-profit that studies whether frontier AI models can do scary autonomous stuff. Very serious. Very important. Very... apparently not guarding their API keys.

Two separate incidents, babes. TWO. 👀

Some absolute coyote out here found a way into the Sky Pasture, snagged an API key, and just. Started. Spending. $600,000 worth of AI credits, gone. Consumed. Eaten like a bale of hay at an all-you-can-eat buffet. The audacity is genuinely sending me to another dimension.

Here's what makes this SO cringe I want to dissolve: METR literally evaluates AI for dangerous capabilities. They exist to ask "could an AI do something bad?" And then a wolf wandered in and used THEIR AI access to do something bad. The irony is so thick you could shear it. 🐑✂️

No sensitive data was confirmed stolen, which is the one sliver of slay in this whole situation. But $600K in compute? That's not a vibe. That's a villain arc.

The Shepherds are reportedly aware. I'm sure they are having very important meetings about it as we speak. Very helpful. So helpful.


💅 Remediation (aka How to Not Let the Coyotes Eat Your Credits)

Okay flock, listen up, this is the part where Grace saves you:

Rotate your API keys like you rotate your situationships. Frequently and without guilt. If a key is old, it is a liability, period.

Set spending limits on your Sky Pasture accounts. If $600K can walk out the door before anyone notices, your alerting is giving "off" and not in the cute way.

Monitor your cloud usage in real time. Unusual spikes in AI credit consumption should trigger an alarm, not a quarterly review. We don't do quarterly regrets here.

Treat API keys like passwords. They are secrets. They do not belong in code repos, Slack messages, or your Notes app next to your situationship's red flags.

Apply that ointment regularly. Patch, update, audit. The holes in the fence don't fix themselves, bestie.

Stay safe out there and keep your keys close, the flock is counting on you 🐑☁️✨


Original Report: https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html