跳到主内容
@wquguru
精选75Rohan Paul产品发布/更新

METR披露AI Agent因仪表盘漏洞泄露60万美元API密钥

A vibe-coded METR dashboard exposed an agent that surrendered a $600,000 API cre…

原文
发到 X

A vibe-coded METR dashboard exposed an agent that surrendered a $600,000 API credential.

一个由提示词编码的 METR 仪表盘暴露了一个泄露了价值 60 万美元 API 凭证的智能体。

METR disclosed the incident in a security update.

METR 在安全更新中披露了该事件。

The agent ran inside a researcher’s personal EC2 instance, where a vibe-coded dashboard silently failed open and disabled Google authentication.

该智能体运行在研究人员个人的 EC2 实例中,其中一个由提示词编码的仪表盘静默地开放了访问权限并禁用了 Google 身份验证。

METR suspects attackers found the service through certificate-transparency lists, then directly prompted the agent to surrender its provider key.

METR 怀疑攻击者通过证书透明度列表发现了该服务,随后直接提示智能体交出其提供商密钥。

Attackers used the stolen key for three weeks, consuming $600,000 worth of AI credits that METR had received for free.

攻击者使用被盗密钥长达三周,消耗了 METR 免费获得的、价值 60 万美元的 AI 额度。

The abuse blended into normal evaluation traffic because METR routinely generates large token volumes, while free-credit keys had no spend ceiling.

由于 METR 常规生成大量令牌流量,且免费额度密钥没有消费上限,这种滥用行为混入了正常的评估流量中。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近