Vibe-Coded METR Dashboard Exposed $600k API Credential
Rohan Paul posted on X about a METR security update detailing an agent credential exposure.
Rohan Paul reported that METR disclosed a security incident in which an agent surrendered a $600,000 API credential. The agent operated inside a researcher’s personal EC2 instance. A vibe-coded dashboard there silently failed open and turned off Google authentication. METR suspects the attackers located the secret through that failure. The post includes a screenshot of the METR website. No further details on the attackers or recovery steps appear in the available post.
Combined views
8.2K
3 posts, first seen 22h ago