AI & agents

METR reports credential theft and a data-access issue

Published
Source
METR
Source type
Incident report

Summary

METR disclosed external attackers’ API-key misuse and a data-access issue. Its investigation found no evidence of sensitive information access. This was not an evaluated AI escaping containment.

Why it matters for our work

Automation makes credentials and permissions operational concerns. Scoped keys and spending records would help us identify problems sooner.

Translated from the Korean original. Summaries may be translated and edited. Commentary reflects our perspective; forecasts remain the source’s views.

Read original (opens in a new tab)