AI Gateways Offer Attackers the Keys to the Kingdom

As a growing number of organizations deploy AI gateways to manage access to foundation models, they are inadvertently creating a new surface for attackers to exploit. A recent incident highlights how a threat actor gained access to an EC2 server hosting an AI gateway connected to Amazon Bedrock services, using the access for cryptomining but potentially setting the stage for more serious compromises.

The investigation, led by Darktrace researchers, revealed that the attacker initially gained access to the EC2 server via brute-force login attempts. Once inside, they downloaded a cryptominer software and connected to a cryptomining pool. However, this incident is likely just the tip of the iceberg – AI gateways are increasingly becoming attractive aggregation points for attackers due to their centralized access to multiple AI providers, high-value API credentials, and enterprise identity integration.

The risks associated with AI gateways are vast and varied. As organizations centralize AI access through these gateways, they expand their attack surface, creating opportunities for attackers to abuse AI workflows, manipulate model outputs, or pivot deeper into the cloud environment. The possibilities range from credential theft and data access to cloud persistence and financial impact through abuse of AI inference services.

For instance, if an attacker gains access to an AI gateway with high-value API credentials, they could potentially query proprietary knowledge bases connected through retrieval-augmented generation (RAG). They might also leverage attached identity and access management (IAM) roles to pivot into broader AWS resources or establish persistence within the cloud environment. The lack of visibility into AI-related activities can make it challenging for security teams to detect these types of attacks.

Darktrace’s investigation showed that the compromised system likely functioned as an AI gateway with access to a much broader range of enterprise assets and data. “Think of them as a mini supply chain,” explains Nathaniel Jones, vice president of security and AI strategy at Darktrace. “AI gateways aggregate capabilities that traditionally existed in separate systems, making them attractive targets for threat actors.”

While the incident investigated by Darktrace was related to cryptomining, it’s essential to recognize the potential for more sophisticated attackers with different objectives. The risks associated with AI gateways are not limited to model poisoning or prompt injection; vulnerabilities and weaknesses in AI infrastructure such as Model Context Protocol (MCP) servers and AI gateways themselves also pose a significant threat.

As organizations continue to deploy AI gateways, it’s crucial to recognize the potential risks and take proactive measures to secure these systems. By doing so, they can reduce the attack surface and prevent more severe compromises. “While cryptomining may have been the payload in this case, the initial access technique could be reused by more sophisticated actors with very different objectives,” Jones warns.

To mitigate these risks, organizations should prioritize visibility into AI-related activities, implement robust security measures to protect AI gateways, and regularly monitor for potential vulnerabilities in AI infrastructure. By taking a proactive approach to securing their AI systems, they can minimize the likelihood of attacks like this incident and ensure the safe deployment of AI technologies within their environments.


Source: Dark Reading — 2026-07-09