{"id":92213,"date":"2026-05-07T08:57:33","date_gmt":"2026-05-07T08:57:33","guid":{"rendered":"https:\/\/diyhaven858.wasmer.app\/index.php\/ai-evaluation-startup-braintrust-confirms-breach-tells-every-customer-to-rotate-sensitive-keys\/"},"modified":"2026-05-07T08:57:33","modified_gmt":"2026-05-07T08:57:33","slug":"ai-evaluation-startup-braintrust-confirms-breach-tells-every-customer-to-rotate-sensitive-keys","status":"publish","type":"post","link":"https:\/\/diyhaven858.wasmer.app\/index.php\/ai-evaluation-startup-braintrust-confirms-breach-tells-every-customer-to-rotate-sensitive-keys\/","title":{"rendered":"AI evaluation startup Braintrust confirms breach, tells every customer to rotate sensitive keys"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div xmlns:default=\"http:\/\/www.w3.org\/2000\/svg\">\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">AI evaluation startup Braintrust has urged customers to revoke and replace their API keys after an earlier breach of customer secrets.<\/p>\n<p class=\"wp-block-paragraph\">According to an email sent to customers Monday and seen by TechCrunch, the startup confirmed \u201cunauthorized access\u201d in one of its Amazon Web Services (AWS) cloud accounts, which contained API keys used by customers for accessing cloud-based AI models.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe\u2019ve communicated with one impacted customer and to date have not found evidence of broader exposure,\u201d read the email.<\/p>\n<p class=\"wp-block-paragraph\">The email asked \u201cevery customer to rotate\u201d any of the API keys that they store with Braintrust.<\/p>\n<p class=\"wp-block-paragraph\">Braintrust disclosed the security incident on its website on Tuesday. \u201cThe incident has been contained, and in the meantime, we\u2019ve locked down the compromised account, audited and restricted access across related systems, and rotated internal secrets.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The company said the cause of the breach is under investigation.<\/p>\n<p class=\"wp-block-paragraph\">Braintrust spokesperson Martin Bergman told TechCrunch that the company sent the email to customers \u201cout of an abundance of caution\u201d and that it \u201cconfirmed a security incident, but there is no evidence of a breach at this time.\u201d<\/p>\n<div class=\"wp-block-techcrunch-inline-cta\">\n<div class=\"inline-cta__wrapper\">\n<p>Techcrunch event<\/p>\n<div class=\"inline-cta__content\">\n<p>\n\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__location\">San Francisco, CA<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__separator\">|<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__date\">October 13-15, 2026<\/span>\n\t\t\t\t\t\t\t<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"wp-block-paragraph\">Braintrust provides a platform designed for companies to monitor AI models and products. Founder and CEO Ankur Goyal previously told TechCrunch that Braintrust is like an \u201coperating system for engineers building AI software.\u201d The startup raised $80 million in a Series B funding round in February, which valued the company at $800 million.<\/p>\n<p class=\"wp-block-paragraph\">Jaime Blasco, the co-founder of cybersecurity startup Nudge Security who received a breach email alert from Braintrust, told TechCrunch that the incident could have \u201cdownstream implications for affected customers,\u201d like AI companies that rely on Braintrust.<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about this breach? Or other data breaches? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.\t\t<\/p><\/div>\n<p class=\"wp-block-paragraph\">Hackers frequently target corporate accounts on cloud services or third-party platforms as an effective way of stealing secrets, like API keys. Once hackers get their hands on API keys, they can log into the company or customers\u2019 systems appearing as if they are legitimate users, without needing to break into the target company\u2019s systems.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">CircleCI, a company that provides development products for software engineers, was hit with a similar cloud data breach in 2023, and similarly asked its customers to rotate \u201cany and all secrets\u201d they stored with the company.<\/p>\n<p class=\"wp-block-paragraph\">More recently, an EU cybersecurity agency said hackers were able to steal 92 gigabytes of data from a compromised AWS account used by the European Commission. The breach affected 29 other EU entities and the data of dozens of internal European Commission clients.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, we may earn a small commission. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AI evaluation startup Braintrust has urged customers to revoke and replace their API keys after an earlier breach of customer secrets. According to an email sent to customers Monday and seen by TechCrunch, the startup confirmed \u201cunauthorized access\u201d in one of its Amazon Web Services (AWS) cloud accounts, which contained API keys used by customers [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":92214,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_daextam_enable_autolinks":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[11],"tags":[],"class_list":["post-92213","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/diyhaven858.wasmer.app\/wp-content\/uploads\/2026\/05\/BraintrustTeamPhoto.jpg","jetpack_sharing_enabled":true,"jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/posts\/92213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/comments?post=92213"}],"version-history":[{"count":0,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/posts\/92213\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/media\/92214"}],"wp:attachment":[{"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/media?parent=92213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/categories?post=92213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/tags?post=92213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}