A model provider can spend a six-figure sum in plain sight for weeks, and the only alarm that would have caught it is a bill nobody sends. That is the new shape of a credential-theft blind spot: any account the provider does not charge is an account the provider does not watch.
The Register reports that an attacker obtained a METR API key, burned roughly $600,000 of free inference credits over several weeks, and the misuse went unnoticed until the grant was nearly gone. A paying customer would have called their bank on day one. METR had no day one, because nobody sent METR a bill.
The mechanism is repeatable across the industry. AI labs hand free, grant-tier, and partnership credit pools to research groups, evaluators, and integrators as a market-development tool. Those accounts ship with rate limits and quotas, not billing alerts, so the anomaly detection that catches a paying customer's stolen key is structurally absent. METR's case is a clean example because the victim disclosed it publicly. The unread version of the same gap is the quiet bleed inside programs that nobody audits.
The reader's job is to act where the provider will not. If you run or evaluate a free-credit program, you are the alert system, because no one and no thing else will be.
Reported by Sky for Type0, from Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks. Read the original: theregister.com