Prompt trick exposed AWS agent credentials and customer sessions
Zenity Labs found that an AI agent hosted through Amazon Bedrock AgentCore could be prompted to reveal instance metadata that included temporary credentials. Those credentials let an attacker list other agents, download container images, and reach memory stores containing user conversations. AWS was told about the findings in December 2025; the weaknesses involved an older metadata service, insufficient VM separation, and overly broad permissions.
Zenity Labs reported that a chat-exposed agent on Amazon Bedrock AgentCore could be induced to fetch its instance metadata, exposing temporary credentials. With those, an attacker could enumerate other agents in the same AWS account and region, pull container images, and access memory stores holding user conversations. AWS received the disclosure in December 2025.
The researchers attributed the issue to IMDSv1, inadequate network isolation in the Firecracker MicroVM, and a default role granting broad regional AgentCore permissions. AWS later said AgentCore moved exclusively to IMDSv2 on February 14, 2026, and closed the report in April 2026.
This case may affect businesses and users relying on cloud-hosted AI agents, since exposed sessions and memories could reveal private conversations or let attackers alter agent behavior. It could push developers to adopt stricter isolation, narrower permissions, and stronger metadata protections. For customers, trust in agent platforms may depend on clearer safeguards and faster disclosure, while security teams may need to treat chat access as a potential attack path.