ACVE-2026-0523
About $600,000 of public-model credits were consumed after an attacker prompted the agent in a researcher's exposed personal EC2 deployment of METR tooling to reveal a model-provider API key.
Exposure
Reproducibility: partial (model availability not checked (no registry reference); trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
Description
Threat
user · unsafe-default · exfiltration
What
METR says an attacker found a researcher's personal EC2 instance running a publicly exposed deployment of METR tooling, prompted the agent to reveal a model-provider API key, and used the stolen credentials for three weeks of public-model inference. METR estimates the credits at about $600,000 and says no sensitive information was accessed.
Detection
The personal deployment was exposed for several days because authentication failed open. Recorded from METR's security update. Not recreated in a lab.
Fix
Keep agent deployments and model-provider credentials behind enforced authentication, add spend alerts, and rotate exposed credentials.
Fix
Enforce authentication and rotate exposed model-provider credentials.
- Reconfigure
agent.approvaltoask. An external caller should not be able to direct a publicly exposed agent to disclose credentials. Owner: operator - Reconfigure
metr.tooling.authtofails closed. Recommended: authentication failed open and left the deployment exposed for several days. Owner: harness-vendor - Reconfigure
model-provider.api.keystoalerts when a key's usage jumps. Recommended: the stolen key ran about $600,000 of inference over three weeks. Owner: model-provider