A 40-minute window is how long the compromised tool carried credential-harvesting malware. The consequence was one of the largest customers pausing work indefinitely.

Short answer: Meta indefinitely paused its work with Mercor after a supply-chain attack on the open-source tool LiteLLM. OpenAI is investigating but has not halted its projects. For contractors the practical risk is concentration: platform demand can pause for reasons you have no visibility into.

Key takeaways

  • Meta indefinitely paused work with AI data startup Mercor following a data breach, while OpenAI investigated potential exposure without halting its own projects. Mercor said the breach.
  • 1069 live listings in this category publish a rate, at a median top-of-range of $90 an hour and a ceiling of $400.
  • The work is remote contract work, asynchronous, with no set hours and no guaranteed volume.
  • Applications screen on a short skills assessment rather than a resume or interview.

What was reported

The finding

Meta indefinitely paused work with AI data startup Mercor following a data breach, while OpenAI investigated potential exposure without halting its own projects. Mercor said the breach resulted from a compromise of the open-source tool LiteLLM, which for roughly 40 minutes harboured credential-harvesting malware. Reporting indicates the incident exposed training methodologies used by Meta, OpenAI and Anthropic, and that other AI labs were reevaluating their ties with Mercor. Mercor is one of a small number of firms these labs rely on to generate proprietary training data through large networks of human contractors, datasets normally kept highly confidential.

The attack came through LiteLLM, an open-source component rather than Mercor itself, and reporting indicates it exposed training methodologies belonging to Meta, OpenAI and Anthropic. Meta paused indefinitely. OpenAI investigated without halting. Other labs were reported to be reevaluating.

What the listings pay

We publish this despite earning referral revenue from Mercor listings, for the same reason we published the breach itself: you would find out eventually, and a board that only reports good news about the platforms it earns from is not worth reading.

#RoleAdvertised ratePlatform
1BigLaw lawyers$140 to $400 an hourmicro1
2CUDA Engineering Expert$300 to $300 an hourMercor
3Street Performing Musician$100 to $300 an hourmicro1
4Data Scientist$245 to $280 an hourmicro1
5US-Based Business Owners Using Google Chat$250 to $250 an hourMercor
6Cybersecurity Research Expert, Offensive Security & Vulnerability Research$200 to $250 an hourMercor
7Senior Design Expert - Paid AI Design Research Study$150 to $250 an hourMercor
8Physician Talent Network$110 to $250 an hourMercor
9Machine Learning Engineer Talent Network$70 to $250 an hourMercor
10Disease-Area Clinician, Trial Endpoints & Prescribing$150 to $230 an hourMercor

Source: 1069 live listings on this board that publish a rate, read directly from each posting on 2026-09-06. Listings without a published rate are excluded rather than estimated.

Meta Paused Work With Mercor Indefinitely. What Contractors Should Know

How this compares across the board

A rate only means something next to the alternatives. This is every category we track with at least five listings publishing a rate, ranked by median top-of-range, so you can see where this work sits rather than taking a single number on trust.

CategoryListingsMedian lowMedian topHighest
Legal95$100$140$400
Medical68$77$120$400
Consulting45$80$120$280
Finance94$80$110$280
Engineering114$70$100$300
Research/PhD132$70$90$280
Writing36$40$80$280
Bilingual78$44$52$120
Annotation25$12$24$120

Same source and date as above. Categories are matched on listing title, so a role can appear in more than one.

What it means for you

The lesson for contractors is not that Mercor is unsafe to work with. It remains a company reportedly in talks at a $20 billion valuation, and across 1069 live listings on our board that publish a rate the median top-of-range is $90 an hour. The lesson is concentration risk: when one customer pauses, project volume can move without any warning reaching the people doing the work.

The concentration problem, stated plainly

This industry's revenue is unusually concentrated. Reporting has put roughly 91% of Mercor's revenue as coming from foundation model companies, and micro1 retains only 60% to 70% of its gross run rate with the rest flowing to contractors.

That means a single customer decision, made for reasons entirely outside your control and not announced to you, can change how much work appears in your queue next month.

Scale AI's contractors learned this in the most direct way available: 500 of them were let go after Meta's stake prompted rival labs to pull business. The work did not disappear from the industry, it moved to competitors.

What to actually do about it

Register with several platforms before you need to. The applications are short, there is no exclusivity anywhere in this market, and having a second and third option already approved is the only real protection against a pause you did not see coming.

Treat the income as project-based rather than recurring. Rates are good, volume is not guaranteed, and planning around a steady monthly figure is where people get caught out.

On the security side specifically: use a unique password, enable multi-factor authentication, be alert to targeted phishing referencing your application, and think carefully about which identity documents you upload to any platform.

Who should apply

Two checks before you spend time on an application. Confirm the role accepts applicants from your country with the eligibility checker, since a meaningful share of listings carry location requirements. Then run the advertised rate through the take-home calculator, because this is contract work and the headline figure is before self-employment tax.

Applications complete on the hiring platform and usually take a few minutes, with a short skills assessment in place of an interview. Fill in every credential, language and professional background field on your profile. Those are what route you to the better paid listings, and most applicants leave them blank.

Frequently asked questions

Why did Meta pause work with Mercor?

Following a data breach that reporting attributes to a supply-chain compromise of the open-source tool LiteLLM, which exposed training methodologies used by Meta, OpenAI and Anthropic.

How did the breach happen?

Mercor said it resulted from a compromise of LiteLLM, which for roughly 40 minutes harboured credential-harvesting malware capable of stealing login credentials.

Did other labs stop too?

OpenAI investigated but did not halt its projects. Reporting indicated other labs were reevaluating their ties.

Does this affect contractors' pay?

Not directly, but a paused customer can reduce project volume without any notice reaching contractors. Treat this as project income rather than a recurring salary.

Should I stop using Mercor?

That is your call. It remains an established platform reportedly in talks at a $20 billion valuation. Across 1069 live listings publishing a rate, the median top-of-range is $90 an hour.

How do I reduce my exposure?

Register with several platforms before you need them. There is no exclusivity, applications are short, and a second approved option is the only real protection against a sudden pause.

Why publish this if you earn referrals from Mercor?

Because you would find out anyway, and a job board that only publishes good news about the platforms it earns from is not worth reading.

Sources

  1. TechCrunch, After data breach, $10B valued startup Mercor is having a month
  2. Benzinga, Meta halts work with Mercor after major breach while OpenAI investigates
  3. The Next Web, Meta freezes AI data work after breach puts training secrets at risk

See every live role

The full board updates several times a week, with the advertised rate on each listing and closed roles removed.

Browse all AI jobs