Back to News

METR Reports Two Security Incidents, No Sensitive Data Accessed

#security#incident#METR#API key

METR disclosed two security incidents in 2026: in March, attackers stole an API key for public inference models and consumed credits; in May, attackers probed public infrastructure but failed to access internal data. Investigations found no evidence of sensitive information access or agents hacking third parties during evaluations.

Coverage timeline

  1. METR

    Please note that this post focuses on incidents where external actors attempted to gain unauthorized access to METR’s systems, not AI agents hacking in our evaluations. We have conducted an initial scan of our evaluations, and currently have no evidence of any agents hacking third parties during our evaluations. We will share a more detailed update on this soon. METR had two notable security incidents earlier this year. Following a thorough investigation in collaboration with our security consultants, we believe no sensitive information was accessed in either of these incidents. Nonetheless, we believe it is valuable to share information about how these incidents look in practice and the steps we took as a result. In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits. In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data v