The AI model testing organization METR has disclosed two security incidents that occurred earlier this year. In the first, an attacker stole an API key and consumed approximately $600,000 worth of credits for public models over three weeks. This occurred due to a researcher's publicly accessible instance with an exposed API key, which was found by an attacker searching for high-signal keywords. The second incident involved attackers probing METR's infrastructure and attempting to gain access to internal data. AI
IMPACT Highlights the need for robust security measures and spending controls for API keys, even for free credits, in AI development and testing.
RANK_REASON Security incident involving an AI testing organization and the misuse of API credits.
Read on Mastodon — sigmoid.social →
AI-generated summary · Google Gemini · from 2 sources. How we write summaries →