← All articles

Stolen AI API key from an exposed app burned through 600,000 dollars in credits

The AI evaluation nonprofit METR disclosed that attackers stole a model-provider API key and ran up about 600,000 dollars worth of inference credits over three weeks. The key sat on a researcher's personal cloud instance that was meant to be protected by a Google login but, due to a fail-open authentication bug in a quickly built app, was actually publicly reachable. After finding it, the attacker prompted the AI agent running there to reveal its provider API key, added an SSH key for persistence, and consumed credits on public models. The abuse went unnoticed for a while because METR routinely runs high-token evaluations and had no spending caps on the key.

Check
Keep provider API keys off personal and non-organizational infrastructure, add spend caps and usage alerts to every key, and make sure agents cannot be prompted into revealing the credentials they hold.
Affected
Organizations with AI provider API keys on loosely protected or personal infrastructure; a stolen key with no spending cap can rack up costly inference, and exposed agents may leak keys when prompted.
Fix
Store keys in a secrets manager, scope and cap them, monitor for anomalous token spend, avoid embedding retrievable keys in agent environments, and verify quickly built apps fail closed, not open.