Tag: AWS

  • Amazon Nvidia Chip Leaseback: $8B SPV, 15% Price Hike

    Amazon’s Nvidia chip leaseback would move roughly $8 billion of Grace Blackwell GPUs into an investor-funded special-purpose vehicle and rent the hardware back, the Financial Times reported. The talks surfaced the same week AWS raised GPU rental rates about 15%. Amazon has guided to roughly $220 billion of 2026 capital spending, up from $131 billion in 2025, and declined to comment on the vehicle.

    Key takeaways

    • The FT puts the vehicle at about $8 billion of Grace Blackwell chips, funded mostly with debt.
    • AWS lifted EC2 Capacity Blocks pricing roughly 15% across A100 through B300 instances.
    • Amazon’s 2026 capex guidance stands near $220 billion, about $20 billion above February.

    What is Amazon’s $8 billion Nvidia chip leaseback?

    It is a sale-and-leaseback on silicon. The Financial Times reported on October 1 that Amazon approached investors about transferring roughly $8 billion of Nvidia Grace Blackwell systems into a special-purpose vehicle, which would raise debt against the hardware. Amazon would then lease the same chips back and keep running them.

    The structure is not signed. The FT described talks in progress, and Reuters reported that Amazon declined to comment. Nvidia also stayed silent. Treat every number below as reported, not filed.

    What makes it notable is the asset. Off-balance-sheet AI financing has so far mostly wrapped buildings, land and power contracts. This one wraps the GPUs themselves.

    Which chips are in the vehicle?

    Per the FT, thousands of Grace Blackwell units already installed across more than a dozen US data centers in five states, including Nevada and Virginia. These are not chips on order. They are racks in production, earning revenue today.

    That detail matters for how a rating agency would look at it. A lender is underwriting a running fleet with a known tenant, not a construction project.

    Who would buy the debt?

    Insurers and pension funds, according to the FT’s account. The pitch is an investment-grade instrument riding on Amazon’s double-A credit, paying a lease stream rather than a corporate coupon. The vehicle carries an equity slice of up to 10% alongside the debt; published accounts of who holds that slice differ, and Amazon has not confirmed the split.

    Why is AWS raising GPU rental prices 15% at the same time?

    Because demand is ahead of supply and memory costs are climbing. Reuters reported Amazon raised EC2 Capacity Blocks for ML rates about 15%, covering Nvidia instances from A100 through B300, with the new pricing effective the following week. The p5.48xlarge instance — eight H100s — was listed at $41.528 per hour in major US regions.

    A 15% price increase on reserved GPU blocks is an unusually blunt move for AWS, which has spent two decades cutting prices as a marketing reflex. It tells you the capacity constraint is real.

    It also tells you something about the leaseback math. Higher rental rates raise the cash flow the leased fleet throws off, which is exactly what makes a lease-backed bond easier to sell. The two stories are not unrelated.

    How does this fit Amazon’s $220 billion capex year?

    It is a rounding error against the capex, and a signal against the balance sheet. Amazon lifted 2026 cash capital spending guidance to about $220 billion, roughly $20 billion above its February figure, citing higher memory-chip costs and demand outstripping capacity. The 2025 comparable was $131 billion.

    Against $220 billion, an $8 billion vehicle moves about 3.6% of one year’s spend. The company is not solving a funding gap here. It is testing whether the GPU itself can be financed as an asset class.

    ItemFigureSource
    Chips in proposed SPV~$8 billion, Grace BlackwellFinancial Times
    Equity slice in vehicleUp to 10%Financial Times
    Locations12+ US data centers, 5 statesFinancial Times
    EC2 Capacity Blocks increase~15%, A100 to B300Reuters
    p5.48xlarge list rate$41.528 per hourReuters
    2026 capex guidance~$220 billionAmazon guidance
    2025 capex$131 billionAmazon
    June 2026 term loan$17.5 billionReuters
    Sterling bond£4.25 billionReuters
    Q2 2026 AWS revenue$42.2 billion, +37% YoYAmazon Q2 release

    Who profits from an off-balance-sheet GPU deal?

    Four groups, in descending order of certainty. The banks arranging it, the credit investors buying an AA-adjacent lease stream, Nvidia, and — if the depreciation assumption holds — Amazon shareholders.

    • Arrangers. Fee income on a novel structure, repeatable across every hyperscaler if it clears.
    • Credit buyers. Investment-grade yield with a technology label, which has been scarce.
    • Nvidia. A new financing channel means customers can absorb more chips per dollar of equity.
    • Amazon. Lease expense instead of depreciation, and capacity that does not consume reported capex.

    Amazon is already the heaviest borrower in the group. Reuters put its cumulative bond issuance near $100 billion, the largest among major cloud providers, on top of a $17.5 billion term loan in June and a £4.25 billion sterling deal. Adding a lease structure on top is not deleveraging. It is relocating leverage.

    What is the catch in leasing back a depreciating chip?

    The residual value. Aircraft leasing works because a narrowbody earns revenue for two decades. Nvidia ships a new architecture roughly every year, and Rubin follows Grace Blackwell. A GPU’s secondary-market value can fall faster than the lease amortizes.

    Defenders answer that investors are lending against Amazon’s credit, not the hardware’s resale price. That is true, and it is also the problem. If the collateral does not really matter, this is unsecured Amazon debt wearing a GPU costume, priced as though it were secured.

    The honest version of the skeptical case is narrower: nobody knows the residual value of a 2026 GPU in 2031, because no fleet that large has ever aged out. The structure prices a curve that does not exist yet.

    Why this matters

    Because it extends a pattern. Meta financed its Louisiana campus with Blue Owl Capital, Broadcom assembled roughly $60 billion of debt for Anthropic chips, and CoreWeave has borrowed against GPUs for years. We covered the Broadcom structure in Broadcom Anthropic Financing: $60B Debt, $42B Loan.

    What is new is the tenant. Meta and Anthropic needed outside capital. Amazon does not. When the best-capitalized buyer in the market starts moving compute off its own books, the question stops being access to funding and becomes how the buildout is being accounted for.

    That total keeps growing. We tracked it reaching roughly $300 billion in Off-Balance-Sheet AI Debt Hits $300B as Big Tech Guarantees Loans. Chip-leasing arrangements are spreading outside the US too, as the $7 billion Tencent-Oracle chip lease showed.

    For investors, the practical consequence is that reported capex is becoming a weaker proxy for how much compute a hyperscaler is actually adding. Two companies with identical capex lines can be carrying very different amounts of compute and very different obligations. This post is reporting and analysis, not financial advice.

    What to watch next

    1. Week of October 5, 2026: the roughly 15% EC2 Capacity Blocks increase takes effect, per Reuters.
    2. Late October 2026: Amazon’s Q3 report. The date has not been officially confirmed; third-party trackers point to October 29. Watch the capex line, AWS growth against Q2’s 37%, and any lease-obligation disclosure.
    3. No fixed date: confirmation that the SPV priced, including arrangers, the equity holder and the lease term. Until a filing or a rating action appears, this remains FT-reported talks.
    4. No fixed date: whether Microsoft or Google follow with GPU-level structures. One copycat deal turns this from an Amazon story into a sector accounting story.

    Frequently asked questions

    Has Amazon confirmed the Nvidia chip leaseback?

    No. The Financial Times reported the talks on October 1, 2026. Reuters reported that Amazon declined to comment and Nvidia did not respond. There is no filing or signed agreement in the public record.

    How much are the chips worth?

    About $8 billion, per the FT — thousands of Nvidia Grace Blackwell units across more than a dozen US data centers in five states, including Nevada and Virginia. The exact unit count has not been reported.

    How much did AWS raise GPU prices?

    Roughly 15% on EC2 Capacity Blocks for ML, spanning Nvidia A100 through B300 instances, effective the week after the announcement. Reuters cited the p5.48xlarge at $41.528 per hour in major US regions.

    Does this reduce Amazon’s debt?

    No. It changes where the obligation sits. Lease payments replace depreciation and on-balance-sheet borrowing, but the cash commitment remains. Amazon has issued close to $100 billion of bonds cumulatively, per Reuters.

    What is Amazon’s 2026 capital spending?

    Roughly $220 billion in cash capex, raised about $20 billion from the February guidance, versus $131 billion in 2025. Amazon cited higher memory-chip costs and demand exceeding available capacity.

    Why would insurers buy GPU lease debt?

    Because the FT reported the paper would be structured to investment grade on Amazon’s double-A credit. The appeal is a long-dated, contractual payment stream from a top-tier tenant rather than exposure to chip resale values.

    Is AWS still growing fast enough to justify this?

    AWS posted $42.2 billion of revenue in Q2 2026, up 37% year over year. Amazon guided Q3 group net sales to $197 billion to $202 billion. The Q3 report will show whether that pace held.

    The bottom line

    Amazon does not need $8 billion. That is the whole point of the story. The company raising GPU rental prices 15% in the same week it shops a chip leaseback is signaling that even a $220 billion capex budget is not keeping up, and that it would rather pay rent than carry the asset.

    Expect the structure to price, and expect imitators. The thing worth watching is not the $8 billion. It is whether a credit market that has never seen a GPU fleet reach end of life is pricing residual risk, or quietly deciding it does not have to.

    Sources

    Wealth Engine researches and drafts with AI tools and checks every figure against the sources above. How we report.

  • AWS Loom Vulnerability Hits CVSS 10: Agent Takeover

    The AWS Loom vulnerability disclosed on October 2, 2026 scores a perfect 10.0 on CVSS. CVE-2026-103956 let any unauthenticated network client take super-admin control of the Loom for AWS agent control plane when no identity provider was configured. Two companion flaws scored 6.2 and 7.6. Amazon also patched a SageMaker command-injection bug. The fix is Loom 1.7.0.

    Key takeaways

    • CVE-2026-103956 scores 10.0 on CVSS 3.1 and 4.0 — the maximum possible.
    • Four AWS CVEs landed at once; three hit Loom, one hit SageMaker Distribution.
    • AWS booked $42.2 billion in Q2 2026 revenue, up 37% year over year.

    What is the AWS Loom vulnerability?

    CVE-2026-103956 is a missing-authentication flaw in Loom for AWS, Amazon’s open-source platform for running enterprise AI agents. On deployments with no identity provider configured, the API skipped authentication checks entirely and processed incoming requests with super-admin privileges. No credentials were required. It was published on October 2, 2026.

    The CVSS 3.1 vector tells the story: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Network-reachable, low complexity, no privileges, no user interaction, scope change, total loss of confidentiality, integrity and availability.

    That combination produces 10.0 on both CVSS 3.1 and CVSS 4.0, according to the CVE record. Perfect tens are rare. Most critical bugs stall at 9.1 or 9.8 because something — a privilege, a click, a local foothold — breaks the chain. Nothing broke this one.

    What is Loom for AWS?

    Loom for AWS is an awslabs project, Apache 2.0 licensed, that Amazon describes as an enterprise-grade platform for building, deploying and operating AI agents. It runs on Amazon Bedrock AgentCore Runtime and AWS Strands Agents, and it is the layer where companies register tools, wire up memory stores and connect agents to each other.

    Architecturally it is a FastAPI backend behind an Application Load Balancer, with a React front end and an Amazon Cognito user pool handling authentication. The repository README documents 21 authorization scopes and RFC 8693 token delegation for downstream resources.

    Cognito is the part that matters here. The flaw triggers when that identity provider is absent — the local-development path that nobody is supposed to expose to the internet, and that someone always does.

    What could an attacker actually do?

    Three things, per the advisory summary. Register malicious tool servers that agents would then call. Read stored integration credentials. Modify the IAM role policies attached to managed agents.

    The third is the one that escalates past Loom. An attacker who can rewrite IAM policies on an agent role is no longer confined to the agent platform. They are inside the AWS account.

    Which other CVEs shipped in the same batch?

    Four in total. Two more Loom bugs require authentication but still leak credentials, and a separate SageMaker Distribution flaw allows one project member to run code in another member’s Space. The table below lists each one with its fixed version.

    CVECVSSComponentIssueFixed in
    CVE-2026-10395610.0Loom for AWSMissing authentication, super-admin takeover1.6.1
    CVE-2026-1039587.6Loom for AWSSSRF to internal endpoints, exposes temporary AWS credentials1.7.0
    CVE-2026-1039576.2Loom for AWSUnsafe OAuth2 discovery, leaks client secrets and access tokens1.7.0
    CVE-2026-104019Not publishedSageMaker DistributionOS command injection in Space startup scripts2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, 4.4.3

    CVE-2026-103958 is the quiet one. It lets a user holding mcp:write or a2a:write scopes force Loom’s backend to connect to arbitrary internal destinations, including container credential endpoints. That is how temporary AWS credentials walk out.

    CVE-2026-103957 abuses OAuth2 discovery. A user with the same write scopes can point Loom at a malicious well-known URL, and the backend obligingly sends OAuth2 client secrets or another user’s access token to the attacker’s endpoint.

    SageMaker Distribution 4.5.x is unaffected, per the advisory coverage. Everything older needs one of the seven listed patch versions.

    Was it exploited?

    No exploitation has been reported. As of the October 2 publication date, CVE-2026-103956 was not listed in CISA’s Known Exploited Vulnerabilities catalog, and no public proof-of-concept had been indexed. That is the current state of the evidence, not a guarantee.

    Here is the part that deserves skepticism. Reporting on the advisory dates the 1.6.1 release that contains the fix to August 4, 2026 — roughly two months before the CVE became public. If that date holds, every self-hosted operator who was not watching the awslabs GitHub releases page ran a 10.0 for weeks without being told.

    Nobody publishes how many Loom deployments skip Cognito, so the blast radius is unknowable from the outside. The honest answer is that the exposure count is zero only until someone scans for it.

    Who wins and who loses?

    Amazon loses narrative ground, not revenue. AWS reported $42.2 billion in Q2 2026 net sales, up 37% year over year, with $16.6 billion in operating income. Andy Jassy told investors “AWS is booming, growing 36.7% year-over-year in Q2 — our fastest growth in 18 quarters.” A GitHub advisory on an Apache-2.0 side project does not dent that.

    What it dents is the pitch. Amazon’s own launch post for the project is titled “Building secure AI agents at scale.” The control plane turned out to be the weakest link in the chain it was built to secure.

    The structural loser is the shared-responsibility model. Loom ships as open source, “as-is without warranties.” A managed AWS service carries an SLA and a patch cadence Amazon owns. A GitHub repo carries neither, and enterprises keep treating the two as interchangeable because both say AWS on the tin.

    Who gains financially?

    • Agent-identity and secrets vendors. Every one of these four CVEs ends in credential exposure. That is the exact pitch of the non-human identity category.
    • AI security software. Gartner’s forecast puts AI-amplified security at $48.5 billion in 2026, scaling to $204.5 billion by 2030 — a 65.3% compound rate.
    • Managed agent runtimes. Every self-hosted control-plane bug is an argument for paying Amazon to run it instead.
    • Security services firms. Post-patch work means rotating OAuth2 secrets, revoking tokens, cycling IAM credentials and auditing CloudTrail. That is billable.

    Note the asymmetry inside the Gartner numbers. Securing AI itself — defending the models and agents rather than using AI to defend everything else — reaches only $16.4 billion by 2030. Roughly twelve dollars of AI-powered defense for every dollar spent protecting the AI doing the defending.

    Is this part of a pattern?

    Yes, and the same week proves it. GitLab patched CVE-2026-90970 on October 2, a CVSS 9.9 flaw in its self-hosted AI Gateway. An authenticated user with Duo Agent Platform access could “escape the prompt template sandbox via a specially crafted flow configuration” and execute arbitrary commands.

    Affected versions run from 18.1.6 through the 19.1 line, plus 19.3 before 19.3.2 and 19.4 before 19.4.1. Patches landed in 19.2.4, 19.3.2 and 19.4.1. GitLab.com and GitLab Dedicated customers were never exposed, per The Hacker News.

    GitLab fixed a near-identical sandbox escape, CVE-2026-1868, back in February — also rated 9.9. Two 9.9s in the same subsystem inside eight months is not bad luck. It is a sign that prompt-template sandboxes are hard to get right.

    The common thread across both: the vulnerable component is the orchestration layer, and in both cases the hosted version was safe while the self-hosted one was not. We saw the same control-plane failure mode in the OpenAI training pause, where a single agent ran unsupervised for 2.5 hours. The disclosure-lag problem is the same one that shaped the OpenAI Medicare breach.

    What to watch next

    Three concrete markers, plus one date. AWS has not published a CVSS score for the SageMaker bug, and CISA has not moved any of the four into its exploited catalog.

    1. Amazon Q3 2026 earnings. Guidance is $197 billion to $202 billion in net sales, 9% to 12% growth. Watch whether agent-platform adoption gets named on the call.
    2. CISA KEV listing. A 10.0 with network reach and no authentication is a scanner magnet. Addition to the catalog would mean exploitation was observed.
    3. A published proof-of-concept. None was indexed at disclosure. The gap between advisory and public PoC is where unpatched deployments get found.
    4. Loom’s next release. Whether 1.7.x makes an identity provider mandatory rather than optional is the real fix. Patching one bug leaves the insecure default in place.

    FAQ

    Does this affect Amazon Bedrock itself?

    No. The flaws are in Loom for AWS, the open-source orchestration platform that runs on top of Bedrock AgentCore Runtime, and in SageMaker Distribution. Bedrock itself was not named in the advisories.

    What version fixes everything?

    Loom for AWS 1.7.0. Version 1.6.1 closes the 10.0 authentication bypass, but the OAuth2 and SSRF flaws need 1.7.0. SageMaker Distribution users need one of the seven listed patch releases, or 4.5.x.

    Am I exposed if I configured Cognito?

    Not to the 10.0 bug. CVE-2026-103956 requires that no identity provider be configured. The other two Loom flaws still apply to authenticated users holding mcp:write or a2a:write scopes.

    What should I do after patching?

    Rotate OAuth2 client secrets, revoke access tokens that may have been exposed, cycle IAM credentials associated with agent roles, and review CloudTrail logs for unexpected tool-server registrations or policy changes.

    Is the GitLab flaw related?

    Not technically. CVE-2026-90970 is a separate prompt-template sandbox escape in GitLab’s self-hosted AI Gateway, rated 9.9. It shares a disclosure date and a theme: the AI orchestration layer is where the critical bugs are landing.

    Does this change the case for managed agent services?

    It strengthens it. In both the Loom and GitLab incidents the hosted path was protected and the self-hosted path was not. Self-hosting buys data control and transfers the patching burden to you.

    Is any AWS customer data confirmed stolen?

    No breach has been reported. These are vulnerability disclosures with patches available, not an incident report. No exploitation has been publicly confirmed as of October 3, 2026.

    The bottom line

    A 10.0 on an agent control plane is the worst possible score on the worst possible component, and it sat patched-but-unannounced for weeks. The money consequence is not an AWS revenue problem — $42.2 billion a quarter growing 37% absorbs this easily.

    The consequence is that the agent-orchestration layer is now the attack surface, and enterprises are deploying it faster than they are securing it. Gartner’s own numbers say firms spend twelve dollars using AI for defense for every dollar spent defending the AI. This week is the bill arriving for that ratio.

    Verdict: patch to 1.7.0 today, then go look at whether anything else in your stack ships with authentication optional. Enterprise agent platforms like Meta’s and always-on agent products like OpenAI’s Dots all run on control planes of their own.

    Sources

    Wealth Engine researches and drafts with AI tools and checks every figure against the sources above. How we report.