AI Model Evaluator METR hit by $600K phishing scam

Published August 31, 2026

METR, a nonprofit that tests AI models for dangerous capabilities, says attackers stole one of its API keys and used it for weeks. The stolen key ran up $600,000 in charges on public AI model access before METR caught it.

Report priority
Medium
Targets
METR

How it works

  • Attackers got hold of an API key that let them run queries against public AI models under METR's account, then kept using that access for weeks before it was shut down.
  • METR has not said publicly how the key was first obtained.

Technical details

In March, attackers obtained an API key METR used for inference on public AI models. They used it to establish a foothold on a system and kept using the stolen credentials for weeks. By the time METR cut off the access, the misuse had run up $600,000 in AI model usage charges. This is METR's own account of what happened.

METR disclosed two incidents on August 31. In March, an attacker compromised an API key scoped to inference on public models (their category 2 data), used it to establish persistence on a system, and retained access for weeks, ultimately racking up $600,000 in model usage costs. In May, attackers probed METR's public-facing infrastructure and made an unsuccessful attempt to reach internal data through an inadvertently exposed endpoint. METR calls both 'near misses' but confirms the March event was a successful compromise, not just reconnaissance.