Skip to content
AI Gateways Offer Attackers the Keys to the Kingdom

AI Gateways Offer Attackers the Keys to the Kingdom

Darkreading Jai Vijayan July 9, 2026

A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data.

As a growing number of organizations deploy AI gateways to manage access to foundation models, all signs point to them becoming yet another surface for security defenders to protect.

Researchers at Darktrace recently investigated an incident where a threat actor gained access to an EC2 server hosting an AI gateway connected to Amazon Bedrock services. The attacker used the access for cryptomining but could just as easily have abused the AI gateway to access connected models and data, manipulate AI workflows, or pivot deeper into the unnamed organization's cloud environment to make it a much more serious compromise.

"This incident should be viewed as the tip of the iceberg," advises Nathaniel Jones, vice president, security and AI strategy and field CISO at Darktrace. "AI gateways increasingly sit at the intersection of identity, cloud infrastructure, proprietary data, and access to multiple foundation models."

As organizations centralize AI access through gateways, expect them to become attractive aggregation points for attackers. "While cryptomining may have been the payload in this case, the initial access technique could be reused by more sophisticated actors with very different objectives," Jones says, ticking off credential theft, data access, and cloud persistence as possibilities.

For organizations racing to AI-enable applications and workflows, the incident is another reminder of how every new AI component in the environment can expand the attack surface . The risks include those tied to AI models themselves, such as model poisoning and prompt injection ; vulnerabilities and weakness in AI infrastructure such as Model Context Protocol (MCP) servers and AI gateways; insecure use of coding agents, and agentic AI more generally.

Darktrace uncovered the incident involving the AI gateway when investigating activity consistent with cryptomining from an externally exposed AWS EC2 instance connected to Amazon Bedrock , a managed AWS service that provides access to AI models from multiple providers via APIs. Organizations use the service to build generative AI apps without having to manage underlying infrastructure.

Though Darktrace was unable to confirm definitively, the attacker appeared to have gained initial access to the EC2 server via brute-force login attempts. The threat actor then downloaded the XMRig cryptominer software on the compromised system and a few minutes later connected to a cryptomining pool. Darktrace's investigation showed the compromised system likely functioned as an AI gateway with access to a much broader range of enterprise assets and data.

"Depending on the permissions granted to the gateway, an attacker might have accessed sensitive prompts and model outputs, stolen API keys, secrets, or cloud credentials, or queried proprietary knowledge bases connected through retrieval-augmented generation (RAG)," Jones says. They could have also leveraged "attached [identity and access management, or IAM] roles to pivot into broader AWS resources, generated significant financial impact through abuse of AI inference services, or established persistence within the cloud environment."

The key takeaway here is not what actually happened, but what could have easily transpired if the attacker decided to leverage the AI gateway. "While cryptomining is noisy and relatively easy to detect, credential theft and cloud persistence would have been far more concerning outcomes."

AI gateways, Jones says, are attractive targets for threat actors because they often aggregate capabilities that traditionally existed in separate systems. For example, they typically have centralized access to multiple AI providers, high-value API credentials, enterprise identity integration access to internal documents and enterprise knowledge, and connectivity to development tools, databases, and software-as-a-service (SaaS) platforms. "Compromising one gateway may provide access to multiple downstream systems without needing to compromise each individually. Think of them as a mini supply chain."

When deploying AI gateways, organizations should make sure not to grant overly broad IAM permissions or expose management interfaces to the Internet, Jones advises. He also advocates use of short-lived API keys instead of long-lived credentials, segmentation between AI infrastructure and production environments, monitoring of AI-specific administrative actions and prompt activity, and treating AI gateways as privileged cloud assets.

"We're already seeing observations across our customer base that reinforce why additional controls need to be in place," Jones says. "The most common risks are not necessarily compromised models or advanced AI attacks. They are employees and business functions exposing sensitive information through entirely legitimate-looking interactions."

Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.

Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.

Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.

His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.

The State of Cloud Security: The Latest Challenges

The total economic impact™ of Snyk

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Governing the Agent; Identity Security in the Age of Autonomous AI

Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything

Practical Zero Trust Implementation on a Budget in the Age of Mythos

Building a Risk Based Vulnerability Management Program

Threat Hunting That Gets Big Results Despite Small Budgets

Extracted Entities