AI observability startup Braintrust confirmed a security incident on May 4, 2026 after attackers accessed an Amazon Web Services account holding customer API keys used to reach cloud-hosted AI models.
What Braintrust said
The company published a trust-center notice May 5, locked down the compromised account, audited related systems, and emailed all customers to rotate any API keys stored with Braintrust. Braintrust told TechCrunch it had contacted one impacted customer and had not found evidence of broader exposure at disclosure time.
Why this matters for AI teams
Braintrust sits in the supply chain between enterprises and model providers—similar to prior CircleCI-style secret-store breaches. Stolen API keys can let attackers run inference, exfiltrate prompts, or pivot into customer cloud tenants appearing as legitimate users.
Immediate steps
- Revoke and reissue every API key you stored in Braintrust.
- Review cloud audit logs for anomalous model calls since early May 2026.
- Enable MFA on provider consoles (OpenAI, Anthropic, AWS Bedrock, etc.).
Canonical record: Braintrust 2026 on BreachHistory.
Sources: TechCrunch, Braintrust trust center