<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Api-Key-Theft on CuraSec</title><link>https://curasec.metacog.co.kr/tags/api-key-theft/</link><description>Recent content in Api-Key-Theft on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 01 Sep 2026 15:28:52 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/api-key-theft/index.xml" rel="self" type="application/rss+xml"/><item><title>METR AI Research Org Loses $600K in Credits After API Key Theft</title><link>https://curasec.metacog.co.kr/insights/2026-09-01-attackers-steal-metr-api-key-and-consume-ai-credits-worth-ab/</link><pubDate>Tue, 01 Sep 2026 15:28:52 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-01-attackers-steal-metr-api-key-and-consume-ai-credits-worth-ab/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No CVE, no exploitation signals, and no software vulnerability involved — this is an operational credential hygiene failure. Useful as a reminder to audit API key scoping, rotation, and spend-alert thresholds for any AI API integrations you own.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or detection surface published; the summary is too thin to generate hunt queries or tuning guidance. The pattern of high-volume AI credit consumption as an abuse signal is worth noting for future alert design, but there is nothing actionable here today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A small non-profit incident, not a systemic vendor breach, so no immediate board action is warranted. The $600K credit-consumption impact illustrates the financial exposure of unmonitored AI API credentials — useful context if your org is maturing AI governance policy.&lt;/li>
&lt;/ul></description></item></channel></rss>