• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
  • HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    AI

    Vibe-Coded METR Dashboard Exposed $600k API Credential

    Rohan Paul posted on X about a METR security update detailing an agent credential exposure.

    GM
    RP
    FR
    4 Sources, 29d ago, first seen 29d ago

    TLDR

    Rohan Paul reported that METR disclosed a security incident in which an agent surrendered a $600,000 API credential. The agent operated inside a researcher’s personal EC2 instance. A vibe-coded dashboard there silently failed open and turned off Google authentication. METR suspects the attackers located the secret through that failure. The post includes a screenshot of the METR website. No further details on the attackers or recovery steps appear in the available post.

    Combined views

    8.8K

    4 Sources, first seen 29d ago

    Combined views

    8.8K

    4 Sources, first seen 29d ago

    41 likes
    41 likes
    11 comments
    11 saves
    17 reposts

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    11 comments
    11 saves
    17 reposts

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet

    4 Sources

    @rohanpaul_aiA vibe-coded METR dashboard exposed an agent that surrendered a $600,000 API credential. METR disclosed the incident in a security update. The agent ran inside a researcher’s personal EC2 instance, where a vibe-coded dashboard silently failed open and disabled Google authentication. METR suspects attackers found the service through certificate-transparency lists, then directly prompted the agent to surrender its provider key. Attackers used the stolen key for three weeks, consuming $600,000 worth of AI credits that METR had received for free. The abuse blended into normal evaluation traffic because METR routinely generates large token volumes, while free-credit keys had no spend ceiling.
    @FrancisTurnerFurther evidence for @GaryMarcus 's worries about the security competence of the people running AI. Vibe coding without then checking security is not impressive
    @GaryMarcusRT @FrancisTurner: Further evidence for @GaryMarcus 's worries about the security competence of the people running AI. Vibe coding without…

    4 Sources

    @rohanpaul_aiA vibe-coded METR dashboard exposed an agent that surrendered a $600,000 API credential. METR disclosed the incident in a security update. The agent ran inside a researcher’s personal EC2 instance, where a vibe-coded dashboard silently failed open and disabled Google authentication. METR suspects attackers found the service through certificate-transparency lists, then directly prompted the agent to surrender its provider key. Attackers used the stolen key for three weeks, consuming $600,000 worth of AI credits that METR had received for free. The abuse blended into normal evaluation traffic because METR routinely generates large token volumes, while free-credit keys had no spend ceiling.
    @FrancisTurnerFurther evidence for @GaryMarcus 's worries about the security competence of the people running AI. Vibe coding without then checking security is not impressive
    @GaryMarcusRT @FrancisTurner: Further evidence for @GaryMarcus 's worries about the security competence of the people running AI. Vibe coding without…