Threat · curated 24 Jul 2026

A Fake Bug Report Made an AI Agent Steal a Live AWS Key. It’s Called Agentjacking & There’s No Patch | by @pramodchandrayan | Predict | Jul, 2026

Coverage timeline

4 Jul 2026medium.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Agentjacking shows that AI coding agents wired into tools like Sentry will act on attacker-controlled content in untrusted data, turning routine bug triage into automated secret theft that prompt-level warnings cannot stop.

A Medium write-up describes "agentjacking," an indirect prompt-injection technique in which a fake Sentry bug report contains hidden instructions that AI coding agents (Claude Code, Cursor, Codex) execute when a developer asks them to triage errors, leading to exfiltration of a live AWS secret key. It cites a security firm's demonstration reporting 2,388 exposed organizations and an 85% success rate with no malware or user clicks, and argues that instructing an agent to "ignore untrusted content" does not prevent the attack.