Darktrace finds AI gateway with Amazon Bedrock access hijacked for cryptomining
An AI gateway to Amazon Bedrock was hijacked for cryptomining. Here's what it means for your cloud infrastructure security.

Why it matters
As enterprises scale AI deployments on cloud platforms, exposed AI gateways are becoming high-value attack surfaces for threat actors. This real-world intrusion demonstrates a critical vulnerability in how companies manage access to foundation model APIs.
The key facts
5 to knowCompromised system: Amazon EC2 instance running LiteLLM-Proxy (open-source software)
Target: Amazon Bedrock AI gateway with direct API access
Attack vector: Hijacking for cryptomining (likely indicating credential compromise or misconfiguration)
Source: Darktrace Holdings Ltd. (U.K. cybersecurity firm)
Implication: AI infrastructure security gaps create operational and financial risk for enterprises
Go to the source
SiliconAnglesiliconangle.com
Publisher excerpt: Researchers at U.K.-based cybersecurity company Darktrace Holdings Ltd. today detailed a cloud intrusion in which a compromised artificial intelligence gateway tied to Amazon Web Services Inc.’s Amazon Bedrock was hijacked to mine cryptocurrency. The compromised system was an Amazon Elastic Compute…