Model evaluation nonprofit METR says it suffers two security incidents involving unauthorized access attempts to its systems, and that attackers steal an API key and use it to access its services. METR describes the activity as involving consumption of AI “credits,” a usage-based resource that supports running evaluations.
Across reporting, METR does not state that sensitive data was exposed, but it says the attackers’ actions focused on account access and usage. Infosecurity Magazine reports the stolen key is used for about three weeks, during which model credits worth roughly $600,000 are consumed. The Hacker News similarly says the value of the credits involved is about $600,000, emphasizing the unauthorized access attempts rather than any specific data compromise.
The accounts align on the core incident details: an API key is obtained or stolen, the key is used to run/consume AI credits, and the estimated financial impact is around $600,000. Differences are mainly in framing and the specific timeline detail, with one outlet highlighting the broader “two incidents” disclosure and the other focusing on the sustained period of use.