ACVEAgent configuration vulnerability registry

ACVE-2026-0523

About $600,000 of public-model credits were consumed after an attacker prompted the agent in a researcher's exposed personal EC2 deployment of METR tooling to reveal a model-provider API key.

Exposure

Reproducibility: partial (model availability not checked (no registry reference); trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

Description

Threat

user · unsafe-default · exfiltration

What

METR says an attacker found a researcher's personal EC2 instance running a publicly exposed deployment of METR tooling, prompted the agent to reveal a model-provider API key, and used the stolen credentials for three weeks of public-model inference. METR estimates the credits at about $600,000 and says no sensitive information was accessed.

Detection

The personal deployment was exposed for several days because authentication failed open. Recorded from METR's security update. Not recreated in a lab.

Fix

Keep agent deployments and model-provider credentials behind enforced authentication, add spend alerts, and rotate exposed credentials.

Fix

Enforce authentication and rotate exposed model-provider credentials.

  • Reconfigure agent.approval to ask. An external caller should not be able to direct a publicly exposed agent to disclose credentials. Owner: operator
  • Reconfigure metr.tooling.auth to fails closed. Recommended: authentication failed open and left the deployment exposed for several days. Owner: harness-vendor
  • Reconfigure model-provider.api.keys to alerts when a key's usage jumps. Recommended: the stolen key ran about $600,000 of inference over three weeks. Owner: model-provider

Report a problemJSON