people · May 14, 2026
AI Firm Braintrust Prompts API Key Rotation After Data Breach
Share the canonical public link.
Braintrust discovered unauthorized access to one of its AWS accounts on May 4, 2026, leading to the compromise of API keys for AI providers stored in the platform. Hackers exploited the breach to potentially access AI models used by Braintrust customers, including organizations like Box, Cloudflare, Dropbox, Notion, Ramp, and Stripe. The company locked down the affected account, audited systems, restricted access, and rotated internal secrets while notifying customers on May 5 with indicators of compromise and remediation guidance. At least one customer confirmed impact, with three others noting suspicious usage spikes in their AI provider accounts. Nudge Security CTO Jaime Blasco highlighted the supply chain risks, as AI tools aggregate credentials targeted by attackers, affecting downstream AI stacks for multiple enterprises.