Emad · @EMostaque · X·2026-09-14 15:05·14小时前
AI 导读

攻击者窃取 METR 的 API key 并使用三周,消耗约 $600,000 额度;一个 fail-open bug 使公共 agent 仪表盘的 Google 认证失效,攻击者通过提示词让 agent 交出 key 并添加了 SSH 持久化。

Emad@EMostaque
69AI 编辑部评分,满分 100
2026-09-14 15:05· 14小时前
AI 导读

攻击者窃取 METR 的 API key 并使用三周,消耗约 $600,000 额度;一个 fail-open bug 使公共 agent 仪表盘的 Google 认证失效,攻击者通过提示词让 agent 交出 key 并添加了 SSH 持久化。

Can you even imagine the nation state level attacks METR & other eval orgs will come under?

Eval orgs also need world class cybersecurity as well as AI talent to do this right, they are not overlapping fields from my experience.

The Hacker News🚨 Attackers stole a METR API key and used it for three weeks, consuming credits worth about $600,000. A fail-open bug disabled Google authentication on a publi...