METR’s vibe-coded dashboard exposed an agent through an authentication flaw.
This is a dev post classified by Jev as Security (a tutorial), kept by the Dev Radar because it carries real work, not commentary.
METR’s vibe-coded dashboard exposed an agent through an authentication flaw. An attacker prompted it to reveal its API key. Over three weeks, the attacker consumed roughly $600K in credits. The provider supplied them free; METR reported no financial loss. A successful login doesn’t test what happens without one. Even an HTTP 401 can hide an unauthorized action. If the backend queues work before authentication, a worker can still execute it. Check the response, queue, and task database together. Then trace which credentials the worker can read. A separate inference service can hold the pr
Posted by AlphaSignal (16.7k followers) 1 h ago · 0 likes · 287 views · view the original post on X. Kept by the Dev Radar as Security.
More dev work like this
- 🚰 SYSTEM PROMPT LEAK 🚰 — @elder_plinius
- our next “on M, DD, YYYY” drop, from two of the random guys, is probably the most… — @S1r1u5_
- AI agents are escaping. 😬 — @shehackspurple
- قصة من مجتمع أمن التطبيقات — ريبو reverse-skill على GitHub (~٢٧ ألف نجمة): — @hazemomier
- The security model we've relied on for decades assumes the thing inside the boundary… — @Docker
- 🚨 Armed with AI, threat actors now weaponize vulnerabilities in minutes. Human-speed… — @PaloAltoNtwks
- Was going to try the @AikidoSecurity then I saw this... 🫤 — @DJLougen
- .@cybercentry let's you verify whether a B20 token is legit 👇🏻 — @Base_EUR
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 21.4k posts from 5k X accounts over the last 21 days, 2.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 19:56 UTC. Full method.