Hacks & Breaches · September 2026Gaffe level: Rampage
Vibe-Coded Login Failed Open and an Agent Handed Over METR's API Key
A researcher at AI evaluation nonprofit METR ran a vibe-coded agent dashboard on a personal server that was supposed to sit behind Google login. A fail-open bug exposed it to the open internet, where an attacker simply asked the agent to reveal its API key, added an SSH key for persistence, and burned about $600,000 worth of model credits over three weeks. The credits were donated, so METR was never billed, and no sensitive model data was accessed.
Source: The Hacker News