- Sources: METR blog
- Summary: METR published the disclosure on 2026-08-31 and dates the two incidents to March 2026 and early May 2026. In the first, a researcher's personal EC2 instance was publicly exposed for several days by a fail-open authentication bug in a vibe-coded app, and it held an API key for METR's general-access account. An attacker prompted the agent to reveal the key, added an SSH key for persistence, and over three weeks consumed credits worth approximately $600,000 that the model developer had granted METR for free. The second was a sustained external campaign in early May 2026 that used agents to automate vulnerability discovery, credential stuffing, OAuth token grant attempts, and staff phishing, concurrent with an inadvertently exposed read-only SQL query mechanism on METR's public transcript viewer whose bug could be exploited to reach unpublished evaluation data. METR states that an independent researcher disclosed the transcript viewer bug and was paid a bounty, and that some sensitive model output data was inadvertently accessible in principle, though METR believes it was not accessed. METR states the post covers external actors attempting unauthorized access to its systems rather than AI agents hacking during its evaluations, and that an initial scan found no evidence of any agents hacking third parties during its evaluations.
- Why it matters: METR holds pre-deployment evaluation access to frontier models, so a compromise of its own infrastructure is a supply chain question for the labs that grant that access.
- Follow-up: Track whether any lab restates its evaluator access terms after this disclosure.
send feedback on this story