METR (Model Evaluation and Threat Research)

Sep 2026 · Graded Attested · Technology and Software · Beyond the filings
METR (Model Evaluation and Threat Research)Sep 2026
A vibe-coded orchestration tool on a researcher's personal AWS instance failed open, silently disabling authentication and parking a METR API key on the public internet; an attacker took the key, added SSH persistence, and burned roughly $600,000 in credits over three weeks. The security perimeter ended where an employee's own cloud account began. Authentication that fails open isn't a control; it's an embossed invitation. As for the May incident, METR learned at the time it was being targeted by attackers potentially seeking financial gain or access to advanced AI models; the organization described this as a "sustained external attack campaign." The attackers used agents to automate reconnaissance and vulnerability discovery, including credential stuffing, OAuth-related attacks, scanning for newly deployed services, and phishing attempts.
AI Model Evaluator METR Hit by Credential Theft, Probing
Not yet quantified
AAttestedTechnology and Software
About this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.
← The complete Beyond the Filings ledger ← Back to the index