Skip to content

How a vibe-coded app let hackers use $600k worth of AI tokens at METR

"Because we were not paying for these tokens, there was no natural token spend ceiling..."

How a vibe-coded app let hackers use $600k worth of AI tokens at METR
Image Credit: https://unsplash.com/@niekdoup

A vibe-coded app with a built in fail-open vulnerability allowed attackers to hijack an AI model API at research non-profit METR and use $600,000 worth of credits before they were caught.

In a security update on 31 August, the organisation admitted one of its researchers running AI agents on a personal EC2 instance had accidentally exposed the API key for its general access AI models account in March.

METR said it had free access to the models in question so did not notice the activity, and added frequent large evaluations and early model access “means we are very acclimated to getting lots of weird rate limit and API errors, many of which are spurious and don’t actually reflect high usage.”

While the incident’s impact appears minor for the AI model evaluator, it is the latest to highlight security failings during AI research following OpenAI’s admission that one of its models had been able to access the internet and breach Hugging Face during testing.

What happened?

This content is for members only

Subscribe
Add The Stack on Google