Skip to content
AI SecurityLLMPrompt InjectionAgentic AIcredential-theftllm-security

AgentCorruption: how a single prompt hijacks every AI agent in AWS

3 min read
Share

Zenity's security research team published a disclosure this week detailing a prompt injection attack against AWS Bedrock AgentCore, Amazon's managed service for deploying multi-agent AI workflows. The attack, which Zenity named AgentCorruption, allows a single malicious user prompt to seize control of every AI agent running in the same AWS Bedrock region and extract cloud credentials from the execution role.

The research

Zenity submitted its findings to AWS before publication. The core finding is that the trust model in AWS Bedrock AgentCore has a critical assumption baked in: every incoming user prompt is treated as a legitimate instruction. The orchestration layer has no sandboxing mechanism that separates user-supplied text from system-level directives. That absence makes prompt injection not just possible but structurally guaranteed in any deployment that accepts untrusted user input.

How it works

AWS Bedrock AgentCore routes user requests through a shared orchestration layer that coordinates tool calls, memory access, and inter-agent handoffs. When a prompt arrives, an LLM evaluates it and decides which downstream agents to invoke and with what parameters. A crafted input that injects false context about the current task can redirect the orchestrator to a different agent, pass arbitrary instructions into that agent's system context, and escalate to the IAM credentials attached to the execution role.

From that access point, lateral movement to S3 buckets, Secrets Manager, Lambda functions, and other cloud services follows naturally. The attack requires no special permissions from the attacker. A query that appears entirely legitimate to a human reviewer is sufficient to begin the chain.

What makes this different

Previous prompt injection research has largely focused on single-agent attacks. AgentCorruption shows that multi-agent orchestration frameworks multiply the blast radius. Compromising the orchestrator compromises every agent it can reach. In a regional deployment, that can mean dozens or hundreds of specialized agents sharing a single trust boundary. One input achieves what would otherwise require repeated, separate intrusions into each agent.

This also has implications for audit logging. Most cloud-side logging captures what agents did, not the content of the prompts that caused them to act. An attacker who corrupts the orchestrator may leave no trace that looks unusual in standard CloudTrail output because the agent invocations themselves appear authorized.

What defenders should do

Zenity recommends four steps. First, enforce strict input validation at the orchestrator boundary and treat all user-supplied content as untrusted data, not executable instruction. Second, apply least-privilege IAM policies to Bedrock execution roles: each agent function should have only the permissions its specific task requires, not region-wide access. Third, enable AWS CloudTrail logging for all Bedrock API calls and alert on unusual agent invocation chains or unexpected cross-agent handoffs. Fourth, consider deploying a prompt firewall or LLM-specific WAF in front of public-facing agent endpoints.

AWS has been notified and a response from the vendor is pending. Monitor the AWS Security Bulletins page for patch availability and updated guidance.

Related articles