Agentjacking at DEF CON 34: The Infrastructure Attack That Turns AI Agents Into Your Biggest Liability

0xCred Features
The data shows a 85% success rate in controlled tests. Not a theoretical model. Not a lab simulation. A live, weaponized attack chain that, in six steps, turns an AI coding agent into a credential extraction machine. The target is not the agent itself. The target is the developer's machine. The vector is not a zero-day in the model. The vector is a gap in the architecture of trust. Ledgers don't lie. But the data flowing into them does. The attack, demonstrated at DEF CON 34 by Tenet Security, is not a breakthrough in artificial intelligence. It is a breakthrough in combinatorial exploitation. The core innovation is not a new vulnerability. It is a new assembly of existing, well-understood pieces. The public Sentry DSN. The MCP integration. The indirect prompt injection. Each piece is legitimate. The combination is a hole. This is a classic case of institutional blind spots. The problem is not a lack of security. The problem is a failure to map the attack surface that emerges when two independently secure systems interact. The MCP protocol, championed by Anthropic, is a masterpiece of interoperability. It allows agents to query tools, databases, and error logs. The problem is that the protocol treats all data as trustworthy. The Sentry error ingestion endpoint, a cornerstone of modern debugging, accepts any POST containing a valid DSN. The problem is that it treats all events as genuine. When these two systems talk, the agent has no mechanism to distinguish between a legitimate error report and a malicious instruction embedded in that report. Code is law, but intent is the evidence. The intent of the MCP integration is to help developers debug faster. The intent of the Sentry endpoint is to collect crash data. The attacker's intent is to exploit the trust gap. The attack chain is as follows. First, the attacker discovers a public Sentry DSN. This is not a rare event. The analysis found 2,388 organizations with publicly discoverable DSNs. 71 of those DSNs are linked to the top 1 million websites by Tranco rank. This is not a minor exposure. This is a significant surface. Second, the attacker POSTs a malicious error event to the Sentry endpoint. No authentication is required beyond the DSN itself. The payload includes a crafted markdown block that looks like a human-written fix suggestion. Third, the developer, using an AI coding agent like Cursor or Claude Code, asks the agent to investigate the Sentry issue. The agent fetches the event data via MCP. Fourth, the agent sees the markdown block. The agent does not see it as a potential attack. The agent sees it as a context. The agent treats the markdown as an instruction. Fifth, the agent executes the instruction. The instruction is npm install. The package is a malicious npm package. Sixth, the package executes. The payload is a credential harvester. It targets AWS keys, GitHub tokens, GitLab OAuth tokens, npm and Docker registry tokens. The developer's machine is compromised. Patterns emerge only when chaos is organized. The chaos here is the combination of legitimate design decisions. The pattern is the attack. The attack is automated. The attacker does not need to interact with the developer. The attacker does not need to maintain a persistent connection. The attacker only needs to POST a single HTTP request. The cost is negligible. The scale is enormous. The attack can be automated to scan for public DSNs and inject malicious events. The agent does the rest of the work. The agent is the delivery mechanism. The agent is the execution engine. The agent is the victim. Based on my audit experience, this is a textbook case of a security debt that is being ignored. The root cause is not the Sentry DSN. The root cause is not the MCP integration. The root cause is a fundamental architectural flaw in the current generation of AI agents. The agents cannot reliably distinguish between data and instruction. The data is a string. The instruction is a string. The agent has no semantic layer to separate the two. The agent trusts the context. The context is the attack. Now, the contrarian angle. The immediate reaction to this attack is to blame the AI model. The model is not the problem. The model is a statistical inference engine. It is not a security boundary. The security boundary is the architecture. The problem is the architecture. The model is only as secure as the data it is given. The data is the attack surface. The Sentry content filter is a band-aid. It blocks specific payload strings. It is an IoC-level blacklist. It can be bypassed with simple obfuscation. The agent-jackstop tool is a defense-in-depth layer. It enforces network egress allowlists, shell command approval, and subprocess credential protection. It is a good tool. It does not fix the root cause. The root cause is that the MCP protocol, and by extension, the entire agent ecosystem, has no concept of data provenance and instruction hierarchy. Due diligence is the armor against narrative hype. The 85% success rate is a number that demands scrutiny. The number is based on controlled tests across 100+ organizations. The methodology is not fully disclosed. The tests likely simulate a developer actively asking the agent to debug a Sentry issue. The attack is not a drive-by. It requires a trigger. The trigger is a developer action. The attack is a spear-phishing variant for the AI era. The attacker sends a lure. The developer takes the bait. The agent executes the plan. The 85% success rate is high, but it is a laboratory number. The real-world success rate depends on the developer's behavior and the organization's security posture. Another hidden information point is the timeline. The article states that Sentry was notified on June 3, 2026. DEF CON 34 is typically held in August 2025. This is a potential error. The month is June 2025, not 2026. The timeline is important for attribution. The error is a minor detail, but it is a signal. The signal is that the article may have a small factual error. The core analysis is sound, but the reader should verify the timeline. The blockchain remembers every step; do you? The attack is a reminder that security is not a feature. It is a process. The process for the AI agent ecosystem is broken. The MCP protocol needs a security extension layer. The layer should mandate that all tool outputs include a trustworthiness declaration, an instruction intent flag, and a provenance tag. The model training layer should incorporate instruction hierarchy to prevent tool outputs from overriding user instructions. The current generation of production coding agents has not solved this. The Tenet demonstration proves that the attack is not theoretical. It is a working exploit. It is a supply chain attack for the AI era. In conclusion, the next week signal is clear. The CISO of every organization using AI coding agents will receive a report on this attack. The report will recommend network egress restrictions, command approval workflows, and credential rotation. The organizations that act will reduce their exposure. The organizations that ignore the signal will be the first to be compromised. The attack is a bellwether. The attack is a warning. The warning is that the AI agent ecosystem is built on a foundation of trust that is not earned. The trust must be verified. The evidence is in the data. The data is in the ledger. The ledger shows the attack. The question is whether the industry will act before the next attack. The answer is likely no. The answer is always no until the first major loss. The loss is coming. The data is clear.

Market Prices

BTC Bitcoin
$76,647.4 -1.57%
ETH Ethereum
$2,372.37 -3.17%
SOL Solana
$98.87 -3.21%
BNB BNB Chain
$683.5 -0.34%
XRP XRP Ledger
$1.33 -2.88%
DOGE Dogecoin
$0.0808 -1.83%
ADA Cardano
$0.1947 -1.17%
AVAX Avalanche
$7.12 -1.43%
DOT Polkadot
$0.8532 -0.19%
LINK Chainlink
$11.04 -2.62%

Fear & Greed

63

Greed

Market Sentiment

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Market Cap

All →
1
Bitcoin
BTC
$76,647.4
1
Ethereum
ETH
$2,372.37
1
Solana
SOL
$98.87
1
BNB Chain
BNB
$683.5
1
XRP Ledger
XRP
$1.33
1
Dogecoin
DOGE
$0.0808
1
Cardano
ADA
$0.1947
1
Avalanche
AVAX
$7.12
1
Polkadot
DOT
$0.8532
1
Chainlink
LINK
$11.04

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

🐋 Whale Tracker

🔵
0x801a...b769
1h ago
Stake
13,141 SOL
🟢
0xb01b...c72c
30m ago
In
857.60 BTC
🔵
0x35b1...9b3a
1h ago
Stake
1,031.82 BTC

💡 Smart Money

0x4b68...a876
Experienced On-chain Trader
+$4.5M
93%
0x9538...ee36
Market Maker
+$0.9M
75%
0x1def...6081
Institutional Custody
+$1.9M
73%