Halil, this is primarily a conventional application, identity, and cloud-control failure with AI-denominated impact. METR reports that fail-open authentication exposed a public EC2-hosted agent dashboard; the attacker instructed the agent to reveal its model-provider key, installed an SSH key, and used the credential for three weeks. The roughly $600,000 was the notional value of donated credits—not a cash payment. The AI-specific element is sensitive-information disclosure through an agent, but authentication failure, exposed secrets, excessive key lifetime, and weak consumption controls closed the kill chain. There is no evidence of autonomous behavior, “rogue AI,” model escape, or a novel jailbreak.
To cap loss within hours: enforce fail-closed authentication with deployment tests; prohibit production credentials on personal infrastructure; broker secrets so agents never receive raw keys; issue narrowly scoped, short-lived credentials; impose hard per-key spend and rate limits; and automatically revoke keys on anomalous geography or consumption. Cloud monitoring should immediately alert on public exposure, authentication disablement, changes to authorized_keys, and unexpected SSH access, followed by automated instance isolation and credential rotation.
METR’s later report of agent-heavy probing—credential stuffing, OAuth-grant attempts, service scanning, and staff phishing—should be tracked as a separate campaign. It demonstrates automation, not attribution to the original attacker or a qualitatively new AI capability. The dangling llms.txt and rogue-endpoint-agent narratives remain hypotheses unless backed by reproducible execution chains, victim telemetry, and proof that an agent actually retrieved and executed attacker-controlled instructions. They should inform threat modeling, but not displace tonight’s priorities.
The CISO decision tonight is: classify this as a critical secrets-management and cloud-exposure incident affecting an AI service, rotate every potentially reachable credential, quarantine and rebuild the host, audit provider usage and persistence, deploy hard consumption caps, and inventory unmanaged agent deployments. Do not brief the board that an AI system “went rogue”; the supported framing is an internet-exposed application leaked a valuable credential.