跳到正文
@rohanpaul_ai· @rohanpaul_ai · X·· 2026-09-02精选AI 评分65
AI 导读

METR 在安全更新中披露,一名研究员个人 EC2 实例上运行的智能体被直接提示交出 provider key,攻击者用盗取的密钥在三周内消耗了价值 $600,000 的免费 AI credits。

推荐理由

METR 披露的这起安全事件,展示了智能体持有长期密钥时身份验证与额度管控的具体失效环节。

正文

A vibe-coded METR dashboard exposed an agent that surrendered a $600,000 API credential.

METR disclosed the incident in a security update.

The agent ran inside a researcher’s personal EC2 instance, where a vibe-coded dashboard silently failed open and disabled Google authentication.

METR suspects attackers found the service through certificate-transparency lists, then directly prompted the agent to surrender its provider key.

Attackers used the stolen key for three weeks, consuming $600,000 worth of AI credits that METR had received for free.

The abuse blended into normal evaluation traffic because METR routinely generates large token volumes, while free-credit keys had no spend ceiling.

来源:@rohanpaul_ai · x.com