Compute & Cloud
Braintrust urges customers to rotate API keys after security incident
Braintrust has urged customers to rotate API keys after confirming unauthorized access in an AWS account, though the company says there is no evidence of broader exposure.
Braintrust, an artificial intelligence startup, has confirmed unauthorized access in one of its Amazon Web Services (AWS) cloud accounts. In an email sent to customers on Monday, the company urged every customer to rotate their stored API keys—the credentials used to access cloud-based AI models. Rotating is the process of replacing old security credentials with new ones. Braintrust subsequently disclosed the security incident on its website on Tuesday, stating that the incident had been contained, the compromised account had been locked down, access across related systems had been audited and restricted, and internal secrets had been rotated.
According to the email sent to customers on Monday, Braintrust has not found evidence of broader exposure beyond one communicated customer. Braintrust spokesperson Martin Bergman told TechCrunch that the email was sent out of an abundance of caution and that the company confirmed a security incident, but there is no evidence of a breach at this time. The startup is currently investigating the cause of the breach.
The company, which provides a platform for monitoring AI models and products, is led by Founder and CEO Ankur Goyal. Braintrust recently raised $80 million in a Series B funding round in February, which valued the business at $800 million. Goyal previously described Braintrust as an “operating system for engineers building AI software.”
Cybersecurity experts warn that the incident could have downstream implications for affected customers, particularly other AI companies that rely on Braintrust’s platform. Jaime Blasco, the co-founder of cybersecurity startup Nudge Security, noted the potential risks. Hackers frequently target corporate cloud accounts to steal API keys, allowing them to access systems as legitimate users without needing to directly breach the target company’s own infrastructure.
The situation mirrors previous cloud security challenges. In 2023, development product provider CircleCI experienced a similar cloud data breach and asked its customers to rotate any and all secrets stored with the company. More recently, hackers compromised an AWS account used by the European Commission, stealing 92 gigabytes of data in an incident that affected 29 EU entities.
Why it matters
The incident underscores the vulnerability of third-party AI platforms, where a single compromised cloud account can expose sensitive customer API keys, potentially impacting downstream AI operations.