Attackers Drain $600,000 in AI Credits After Stealing METR API Key
The AI safety non-profit says intruders got into a staff laptop and a code repository, but no sensitive research data was taken.

Key points
- METR, a US non-profit that tests advanced AI models, disclosed two break-ins where outsiders got into its systems.
- Attackers stole an API key, a kind of digital password used by software, and burned through roughly $600,000 of AI credits.
- A second intrusion involved unauthorised access to a private code repository belonging to the organisation.
- METR says no sensitive research data or model evaluation results were taken in either incident.
- The non-profit is rotating credentials and tightening internal access controls in response.
METR, the Model Evaluation and Threat Research group, has told the public that attackers hit its systems twice this year. The organisation tests frontier AI models, the largest and most capable systems built by companies like OpenAI and Anthropic, to see whether they can carry out long, complex tasks on their own.
In the first incident, criminals got hold of an API key belonging to METR. An API key is essentially a password that lets one piece of software talk to another. In this case, the key gave whoever held it the ability to spend money on AI services on METR's tab.
They spent a lot. Around $600,000 in AI credits were consumed before the theft was caught, according to disclosure first reported by The Hacker News.
The second incident was different. Attackers gained access to a private source code repository, meaning the internal store where METR's software is written and kept. The non-profit says no sensitive information was taken.
Who is METR and why would anyone target them?
METR is a small research non-profit that stress-tests the world's most powerful AI models. Its work sits close to the labs building those systems and to governments trying to write rules for them. That makes both its research and its cloud accounts attractive targets.
The name stands for Model Evaluation and Threat Research, and is pronounced "Meter". The group is best known for measuring how long a task an AI system can carry out unsupervised, a benchmark that policymakers now cite when discussing AI risk.
How did the attackers get in?
METR says the first intrusion started with a compromised staff laptop. From that machine, the attackers pulled an API key that was stored locally, then used it to run up a bill on AI services.
The organisation has not publicly detailed how the code repository was accessed in the second incident, other than to say it involved unauthorised entry by an outside party. No customer data is involved, because METR does not run a consumer product.
What was actually taken?
Money, in effect, and access. Not research.
| Incident | What attackers reached | Impact |
|---|---|---|
| First | A METR API key on a staff device | About $600,000 in AI credits spent |
| Second | A private source code repository | No sensitive data taken, per METR |
METR says its model evaluation results, unpublished research, and information shared under agreement with AI labs were not exposed.
Should ordinary people be worried?
No, not directly. METR does not hold accounts, payment details or personal records for members of the public. The damage here was financial and reputational, borne by the non-profit and the AI vendor whose credits were drained.
The wider lesson matters more. API keys are the quiet plumbing of modern software, and when one leaks from a developer's laptop, the bill can climb into six figures within hours. Companies that use AI services should treat those keys with the same care as bank credentials.
What is METR doing now?
The non-profit is rotating affected credentials, reviewing how secrets are stored on staff devices, and tightening who can reach internal repositories. It has also said it will share more technical detail as its investigation continues.
For a research group whose job is to warn the world about capable AI systems being misused, being on the receiving end of a straightforward credential theft is an awkward moment. It is also a common one.



