One prompt exposes AWS agent credentials; AWS calls it documented behavior amid a $220 billion capex plan
Researchers say one plain-English prompt made a Bedrock agent surrender its live cloud credentials, and the final fix landed nine months after the first report. The same day, AWS's CEO Matt Garman defended the spending plan behind the platform.
Vincent Jiang · 3 min read
One prompt, the whole account
On October 8, Zenity Labs said one plain-English prompt made a public-facing agent hand over its live cloud credentials, which the researchers exported and confirmed working outside AWS+1.78% — AWS, up 1.78 percent today 12. The default role attached to AgentCore, Amazon's managed agent service, then let them copy every agent's source code across one AWS account and region, read users' private conversations, pull secrets and plant memories that outlasted the chat 2. Zenity says it has seen no evidence of the flaw being exploited in the wild 3.
Unit 42 had already reported, on September 18, that AgentCore's built-in shell tool runs as root by default, in the same memory space where credentials resolve to plaintext: "It is the out-of-the-box state" 1. Zenity's research director, Tamir Ishay Sharbat, called the credential grab "so freakin' easy" at the SecTor conference in Toronto 3.
AWS points at the documentation
A spokesperson said the research "inaccurately paints expected and documented behavior as a vulnerability," and that an agent reaches another account's resources only where the developer granted permissions on both sides 1. AWS closed Unit 42's September report as informative 1.
The calendar is the harder part. Zenity reported the credential path on December 25, 2025, and the broad default role on January 12; AWS moved new agents to IMDSv2-only on February 14, closed the metadata report as informative in April, left the default role unchanged in June and narrowed it only by September 29 2. No CVE was issued 2.
Most tenants never rewrite the defaults
Under the shared responsibility model, the sandbox is Amazon's to fix and the defaults are the tenant's to rewrite, and most never will, in Info-Tech analyst Fred Chagnon's judgment 1. The audit that remains is consultant Justin Greis's checklist: what identity the agent carries, what it can reach, change and remember, and what happens if it is compromised 1.
A $220 billion bet on the same platform
The same day, AWS chief Matt Garman told the a16z podcast the company plans roughly $220 billion of 2026 capital spending, on revenue growing 37%, with no customer above a single-digit share and Bedrock revenue up 170% quarter-over-quarter in some periods 4.
Amazon's quarterly capex has nearly quintupled in three years
Data
| Capital expenditure | |
|---|---|
| Q3 '23 | $11.3B |
| Q4 '23 | $13.35B |
| Q1 '24 | $13.94B |
| Q2 '24 | $16.39B |
| Q3 '24 | $21.28B |
| Q4 '24 | $26.05B |
| Q1 '25 | $24.26B |
| Q2 '25 | $31.37B |
| Q3 '25 | $34.23B |
| Q4 '25 | $38.47B |
| Q1 '26 | $43.23B |
| Q2 '26 | $53.08B |
Amazon's filings put consolidated capital spending at $53.1 billion in the June quarter, nearly five times the Q3 2023 pace 5.
Rivals are moving onto the same defaults
Demand is contracted, on Garman's telling: the AI run rate topped $15 billion in the first quarter and ran at $25 billion by early August, with capacity spoken for into 2028 and Trainium sold out 46. OpenAI's$1.18T — OpenAI, private, latest valuation $1.18T agents became the newest tenants in September, running on AgentCore inside customers' existing AWS permissions, with Salesforce+0.27% — Salesforce, up 0.27 percent today named as a customer 78.
Cloudflare fixed a comparable cross-tenant leak the same month, so isolation failure is an industry pattern 9. The OpenAI agents reach general availability at re:Invent in December 8, which leaves tenants the weeks before then to audit execution roles. Amazon is spending $220 billion to make agents autonomous, and the fine print says the damage belongs to the tenant 14.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.


