An attacker obtained a METR API key and consumed approximately $600,000 worth of service credits before the unauthorized activity was detected weeks later. The incident highlights a significant security gap in monitoring and access controls at the AI infrastructure provider. The Register has not yet reported on the full details of how the breach was discovered or what remediation measures were implemented.