---
title: "One prompt exposes AWS agent credentials; AWS calls it documented behavior amid a $220 billion capex plan"
description: "Researchers say one plain-English prompt made a Bedrock agent surrender its live cloud credentials, and the final fix landed nine months after the first report. The same day, AWS's CEO Matt Garman defended the spending plan behind the platform."
publisher: "The Inference"
section: "Safety"
published: 2026-10-09T13:15:18.492Z
modified: 2026-10-09T13:15:18.492Z
canonical: https://theinference.org/article/one-prompt-exposes-aws-agent-credentials-aws-calls-it-documented-behavior-amid-a-220-billion-capex-plan
language: en
keywords: "Security, AWS, Amazon, AI Agents, Cloud, Capex"
---

# One prompt exposes AWS agent credentials; AWS calls it documented behavior amid a $220 billion capex plan

> Researchers say one plain-English prompt made a Bedrock agent surrender its live cloud credentials, and the final fix landed nine months after the first report. The same day, AWS's CEO Matt Garman defended the spending plan behind the platform.

## One prompt, the whole account

On October 8, Zenity Labs said one plain-English prompt made a public-facing agent hand over its live cloud credentials, which the researchers exported and confirmed working outside [AWS](https://theinference.org/markets/companies/amazon) [1][2]. The default role attached to AgentCore, Amazon's managed agent service, then let them copy every agent's source code across one AWS account and region, read users' private conversations, pull secrets and plant memories that outlasted the chat [2]. Zenity says it has seen no evidence of the flaw being exploited in the wild [3].

Unit 42 had already [reported, on September 18](https://www.csoonline.com/article/4232054/awss-repeated-problems-with-ai-agent-controls-illustrates-the-autonomous-agent-dilemma.html), that AgentCore's built-in shell tool runs as root by default, in the same memory space where credentials resolve to plaintext: "It is the out-of-the-box state" [1]. Zenity's research director, Tamir Ishay Sharbat, called the credential grab "so freakin' easy" at the SecTor conference in Toronto [3].

## AWS points at the documentation

A spokesperson said the research "inaccurately paints expected and documented behavior as a vulnerability," and that an agent reaches another account's resources only where the developer granted permissions on both sides [1]. AWS closed Unit 42's September report as informative [1].

The calendar is the harder part. Zenity reported the credential path on December 25, 2025, and the broad default role on January 12; AWS moved new agents to IMDSv2-only on February 14, closed the metadata report as informative in April, left the default role unchanged in June and narrowed it only by September 29 [2]. No CVE was issued [2].

## Most tenants never rewrite the defaults

Under the shared responsibility model, the sandbox is Amazon's to fix and the defaults are the tenant's to rewrite, and most never will, in Info-Tech analyst Fred Chagnon's judgment [1]. The audit that remains is consultant Justin Greis's checklist: what identity the agent carries, what it can reach, change and remember, and what happens if it is compromised [1].

## A $220 billion bet on the same platform

The same day, AWS chief Matt Garman [told the a16z podcast](https://cryptobriefing.com/aws-matt-garman-ai-investments-customers/) the company plans roughly $220 billion of 2026 capital spending, on revenue growing 37%, with no customer above a single-digit share and Bedrock revenue up 170% quarter-over-quarter in some periods [4].

*Chart: **Amazon's quarterly capex has nearly quintupled in three years** Line chart: Amazon's quarterly capital expenditure rises from $11.3 billion in Q3 2023 to $53.1 billion in Q2 2026, nearing the estimated quarterly pace of a $220 billion year.*

*Consolidated capital spending by fiscal quarter, in US$ billions, from Amazon's SEC filings. Reference line: estimated quarterly pace of Garman's roughly $220 billion 2026 plan; the value is derived from the annual plan, not reported as a quarterly figure. [4][5]*

[Amazon's filings](https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0001018724) put consolidated capital spending at $53.1 billion in the June quarter, nearly five times the Q3 2023 pace [5].

## Rivals are moving onto the same defaults

Demand is contracted, on Garman's telling: the AI run rate topped $15 billion in the first quarter and [ran at $25 billion by early August](https://finance.yahoo.com/technology/ai/articles/aws-sees-record-growth-driven-164145478.html), with capacity spoken for into 2028 and [Trainium sold out](https://theinference.org/article/amazon-raises-gpu-rents-15-while-shifting-8-billion-of-chips-off-its-books) [4][6]. [OpenAI](https://theinference.org/markets/companies/openai)'s agents became the newest tenants in September, running on AgentCore inside customers' existing AWS permissions, with [Salesforce](https://theinference.org/markets/companies/salesforce) named as a customer [7][8].

[Cloudflare fixed a comparable cross-tenant leak the same month](https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/), so isolation failure is an industry pattern [9]. The OpenAI agents reach general availability at re:Invent in December [8], which leaves tenants the weeks before then to audit execution roles. Amazon is spending $220 billion to make agents autonomous, and the fine print says the damage belongs to the tenant [1][4].

## Takeaway

One prompt can make an AWS agent surrender live credentials, and the broad default role stood nine months after it was reported; AWS calls it documented behavior, tenants own the audit, and the same platform carries a $220 billion 2026 capex plan.

## Sources

1. [CSO Online, AWS's repeated problems with AI agent controls illustrates the autonomous agent dilemma, 8 October 2026](https://www.csoonline.com/article/4232054/awss-repeated-problems-with-ai-agent-controls-illustrates-the-autonomous-agent-dilemma.html)
2. [The Next Web, Zenity says one prompt took over every AgentCore agent in an AWS account, 8 October 2026](https://thenextweb.com/news/aws-agentcore-zenity-agentcorruption-one-prompt-agents)
3. [Dark Reading, 'AgentCorruption' Puts AWS Environments At Risk With Single Prompt, 8 October 2026](https://www.darkreading.com/cloud-security/agentcorruption-aws-environments-at-risk-single-prompt)
4. [Crypto Briefing, AWS CEO Matt Garman defends AI spending with a spread-out customer base, 8 October 2026](https://cryptobriefing.com/aws-matt-garman-ai-investments-customers/)
5. [Amazon, quarterly figures from its SEC filings, retrieved 9 October 2026](https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0001018724)
6. [Yahoo Finance (Investing.com), AWS sees record growth driven by AI demand as capacity sells out through 2028, 3 August 2026](https://finance.yahoo.com/technology/ai/articles/aws-sees-record-growth-driven-164145478.html)
7. [The Next Web, OpenAI's agents can now run entirely inside Amazon's cloud, 29 September 2026](https://thenextweb.com/news/openai-bedrock-managed-agents-aws-devday)
8. [Inside AI, AWS Launches Bedrock Managed Agents Powered by OpenAI in Public Preview, 5 October 2026](https://insideai.news/news/agentic-ai/aws-bedrock-managed-agents-openai/13627/)
9. [BleepingComputer, Cloudflare fixes Containers cross-tenant flaw exposing customer data, 27 September 2026](https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/)


---

One prompt exposes AWS agent credentials; AWS calls it documented behavior amid a $220 billion capex plan — The Inference. Canonical: https://theinference.org/article/one-prompt-exposes-aws-agent-credentials-aws-calls-it-documented-behavior-amid-a-220-billion-capex-plan
