Hackers Broke Into an AI Gateway and Found a Door to Everything
A cryptomining attack on an Amazon cloud server was almost certainly the least damaging thing the criminals could have done. Security researchers say AI gateways are becoming one of the most overlooked entry points in enterprise computing.

Key points
- Researchers at Darktrace investigated a 2025 incident in which criminals broke into an Amazon Web Services cloud server acting as an AI gateway, a system that manages access to multiple artificial intelligence models at once.
- The criminals used the server to run cryptomining software, which secretly uses a company's computing power to generate cryptocurrency, but Darktrace says far worse outcomes were within reach.
- Credentials were likely guessed or brute-forced, meaning the attackers hammered the login page with password combinations until one worked.
- Had they chosen a quieter path, the attackers could have stolen API keys (the digital passcodes that let software talk to other software), read private company documents, or moved deeper into the organisation's cloud accounts.
- Darktrace's Nathaniel Jones describes AI gateways as "a mini supply chain": breaking into one can expose dozens of connected systems without touching any of them directly.
Something quietly dangerous happened on an Amazon cloud server not long ago. Criminals got in, planted cryptomining software, and started making money off the company's electricity bill. Boring, almost. Except the server they chose was an AI gateway.
An AI gateway is the switchboard an organisation puts in front of its artificial intelligence tools. Instead of connecting every internal system directly to an AI model, a company routes everything through one central point. Tidy. Efficient. And, as Darktrace's investigation shows, a spectacular target.
Darktrace, a cybersecurity firm, spotted unusual activity on an externally exposed Amazon EC2 instance, which is a virtual computer rented from Amazon's cloud platform, connected to Amazon Bedrock. Bedrock is Amazon's managed service that lets businesses plug into AI models from multiple providers without running the underlying hardware themselves. XMRig, a well-known cryptomining tool, was downloaded and connected to a mining pool within minutes of the breach.
We first covered this incident on 9 July; this story goes deeper on what the gateway's architecture made possible.
How did the hackers get in?
Darktrace couldn't confirm the exact method, but evidence points to a brute-force login attack. Strong credentials and multi-factor authentication (MFA, a second verification step beyond a password) would very likely have stopped it cold.
The cryptomining was noisy and showed up fast. But Jones warns the same access could've enabled things much harder to detect: reading sensitive prompts and AI outputs, copying cloud credentials, or using the gateway's built-in permissions to reach adjacent systems.
That last point matters most. AI gateways typically hold API keys for multiple providers, connections to internal documents and databases, and integrated identity permissions across cloud services. One door in, many rooms available.
Should you worry?
For employees and customers of companies running this infrastructure, the practical question is whether your employer treats its AI tools with the same security discipline applied to payroll or customer databases. If the answer is vague, press on it.
Jones is direct: the most common risks aren't exotic AI attacks. They're everyday systems left slightly too open for slightly too long. Cryptomining announces itself; credential theft and cloud persistence don't.



