WorkJuly 9, 2026via SiliconAngle

Darktrace finds AI gateway with Amazon Bedrock access hijacked for cryptomining

Why it matters

As enterprises scale AI deployments on cloud platforms, exposed AI gateways are becoming high-value attack surfaces for threat actors. This real-world intrusion demonstrates a critical vulnerability in how companies manage access to foundation model APIs.

Key signals

  • Compromised system: Amazon EC2 instance running LiteLLM-Proxy (open-source software)
  • Target: Amazon Bedrock AI gateway with direct API access
  • Attack vector: Hijacking for cryptomining (likely indicating credential compromise or misconfiguration)
  • Source: Darktrace Holdings Ltd. (U.K. cybersecurity firm)
  • Implication: AI infrastructure security gaps create operational and financial risk for enterprises

The hook

An AI gateway to Amazon Bedrock was hijacked for cryptomining. Here's what it means for your cloud infrastructure security.

Researchers at U.K.-based cybersecurity company Darktrace Holdings Ltd. today detailed a cloud intrusion in which a compromised artificial intelligence gateway tied to Amazon Web Services Inc.’s Amazon Bedrock was hijacked to mine cryptocurrency. The compromised system was an Amazon Elastic Compute Cloud instance named “LiteLLM-Proxy” that ran the open-source LiteLLM software and carried an instance […]

The week's key stories, every Friday.

For practitioners and enthusiasts — free, in your inbox.

Free forever. No spam.