Claude Code · Broadcom · Claude · Amazon · OpenAI · The Register
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
The model provider gave METR the credits for free.
Key facts
- AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits
- In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” the nonprofit disclosed in a Monday report
- METR (short for Model Evaluation and Threat Research) found no evidence that the attackers accessed sensitive information in either incident, and the org said it investigated both with security
- METR researchers worked with OpenAI to investigate how its agents hacked Hugging Face, and on Monday, it disclosed two of its own security snafus
Summary
Virtualization Broadcom pledges to lock down open source Python, Java libraries. Security Researcher shows how Claude Code can be tricked simply by asking it to summarize a website. NETWORKS A lot of datacenter networks are run by absolute clowns. Ai and ml OpenClaw 2.0 pours glitter on slow-burning security dumpster fire. AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000.