WorkJuly 9, 2026via SiliconAngle
Darktrace finds AI gateway with Amazon Bedrock access hijacked for cryptomining
Why it matters
As enterprises scale AI deployments on cloud platforms, exposed AI gateways are becoming high-value attack surfaces for threat actors. This real-world intrusion demonstrates a critical vulnerability in how companies manage access to foundation model APIs.
Key signals
- Compromised system: Amazon EC2 instance running LiteLLM-Proxy (open-source software)
- Target: Amazon Bedrock AI gateway with direct API access
- Attack vector: Hijacking for cryptomining (likely indicating credential compromise or misconfiguration)
- Source: Darktrace Holdings Ltd. (U.K. cybersecurity firm)
- Implication: AI infrastructure security gaps create operational and financial risk for enterprises
The hook
An AI gateway to Amazon Bedrock was hijacked for cryptomining. Here's what it means for your cloud infrastructure security.
Researchers at U.K.-based cybersecurity company Darktrace Holdings Ltd. today detailed a cloud intrusion in which a compromised artificial intelligence gateway tied to Amazon Web Services Inc.’s Amazon Bedrock was hijacked to mine cryptocurrency. The compromised system was an Amazon Elastic Compute Cloud instance named “LiteLLM-Proxy” that ran the open-source LiteLLM software and carried an instance […]