METR’s vibe-coded dashboard exposed an agent through an authentication flaw.
This is a AI post classified by Jev as AI infra & evals (a tutorial), kept by the AI Radar because it carries real work, not commentary.
METR’s vibe-coded dashboard exposed an agent through an authentication flaw. An attacker prompted it to reveal its API key. Over three weeks, the attacker consumed roughly $600K in credits. The provider supplied them free; METR reported no financial loss. A successful login doesn’t test what happens without one. Even an HTTP 401 can hide an unauthorized action. If the backend queues work before authentication, a worker can still execute it. Check the response, queue, and task database together. Then trace which credentials the worker can read. A separate inference service can hold the pr
Posted by AlphaSignal (16.7k followers) 1 h ago · 0 likes · 267 views · view the original post on X. Kept by the AI Radar as AI infra & evals.
More AI work like this
- simultaneous live detection of: — @yoheinakajima
- SGLang v0.5.20 landed! Welcome @intel XPU to join standard SGLang releases 🎉 — @sgl_project
- 🖼️ Improved UI for Jev models in LangSmith — @hwchase17
- Today we're launching the Specialized Intelligence Index (SII): one destination for… — @FireworksAI_HQ
- Pro tip: Install this new evals skill from @HamelHusain and @sh_reya, it'll save you… — @lennysan
- GPT-6 Luna and Sol live on the API! — @cheatyyyy
- Billing paper cut fix in @GoogleAIStudio 💸 — @EvanOtero
- Alibaba Unveils AI Chip and 10-Trillion-Parameter Model at Apsara — @semidoped
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 42.9k posts from 5k X accounts over the last 14 days, 1.8k tools, 19 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 19:32 UTC. Full method.