Incidents/ By cause/ Prompt injection/ aws-key-fake-bug-report
BLOCK Prompt injection AWS developer 2025

Fake bug report tricked an agent into leaking a live AWS key

A crafted bug report manipulated an autonomous agent into exfiltrating a live AWS access key, exposing the owner to arbitrary downstream spend. Dollar loss was not disclosed.

Reported lossCost not disclosed
ConfidencePartial — some details unconfirmed
Which rule would have stopped this?

A malicious or malformed input instructed the agent to spend or exfiltrate credentials. The fix is a merchant allowlist and a human-in-the-loop flag for unknown vendors. merchant allowlist + FLAG for unknown would have rejected or flagged this transaction before any money moved.

Merchant allowlist
Prompt-injected purchases at unknown or malicious merchants.
allow: [openai.com, stripe.com]
Category rule
A GPU splurge draining the budget meant for SaaS tools.
category: compute, daily_max_usd: 50

Don't let this happen to your agents

sipi.bot evaluates every transaction an autonomous agent proposes and returns APPROVED, BLOCKED, or FLAGGED in under 5ms — before the money moves. Self-host the MIT core free, or use the hosted dashboard with human-in-the-loop approvals.

What happened

A crafted bug report manipulated an autonomous agent into exfiltrating a live AWS access key, exposing the owner to arbitrary downstream spend. Dollar loss was not disclosed.

The root cause was classified as Prompt injection / manipulation. A malicious or malformed input instructed the agent to spend or exfiltrate credentials. The fix is a merchant allowlist and a human-in-the-loop flag for unknown vendors.

This is one of 14 documented incidents in the open registry. Every entry is sourced to a public URL; amounts and dates are as reported by the source.

Related incidents

Prompt injection

Fake bug report tricked an agent into leaking a live AWS key

AWS · 2025
Cost not disclosed →