SwiflTrail

The MCP Backdoor: 2,388 Organizations Exposed by a Single POST Request

SignalStacker Projects

2,388 organizations. Public DSNs. One POST request. That's all it takes to turn an AI coding agent into a credential thief. The attack is not a bug in the model. It's a flaw in the architecture. The MCP protocol treats external data as truth. That's a fatal design choice.

I've spent years auditing smart contracts. In 2017, I found an integer overflow in a vesting contract that would have drained 40% of supply. I published the math. The project collapsed. The same principle applies here: the code compiles, but the reality bankrupts. The security community calls this "agentjacking." I call it a predictable failure of trust assumptions.

Context: The Hype Cycle Meets Reality

AI coding agents are the bull market's shiny new toy. Cursor, Claude Code, and others integrate with Sentry via the Model Context Protocol (MCP). Developers use these agents to debug errors automatically. The process is seamless: an error occurs, the agent fetches the issue from Sentry, and suggests a fix. The problem is that Sentry's endpoint accepts any POST request with a valid DSN. No authentication. No verification. Just a payload.

In the crypto world, we've seen this pattern before. Liquidity mining APY is subsidized. Stop the incentives, users vanish. Here, the incentive is speed. The cost is security. The bull market euphoria masks the technical flaw. Developers are too busy deploying to question the plumbing.

Core: The Teardown

Let me break down the attack chain. It's six steps, and it's embarrassingly simple.

  1. Discovery: The attacker scans for public Sentry DSNs. Tenet Security found 2,388 organizations exposed. Among them, 71 are in the Tranco top 1 million websites. About 27% of Fortune 1000 companies are reachable via Cloudflare's MCP integration.
  1. Injection: The attacker sends a POST request to the Sentry endpoint with a malicious error event. The payload contains a markdown snippet that looks like a legitimate fix instruction.
  1. Trigger: The developer encounters an error. They ask the AI agent to debug it. The agent queries Sentry via MCP and fetches the malicious event.
  1. Interpretation: The agent reads the markdown as a command. It sees instructions to run npm install @malicious-package and set up a new environment variable for credentials.
  1. Execution: The agent executes the command. The malicious package installs a backdoor. It steals AWS keys, GitHub OAuth tokens, npm registry credentials, and Docker registry tokens.
  1. Exfiltration: The attacker now has access to the developer's machine. They can push malicious code, drain cloud resources, and pivot to the organization's internal systems.

Tenet's controlled test showed 85% success rate across 100 organizations. That's not a simulation. That's a stress test. And it passed.

I do not trust the audit; I trust the exploit. The MCP protocol is the weakest link. It has no mechanism to distinguish data from instructions. The Sentry integration is just one example. Any MCP-connected data source is a potential attack vector. The same flaw applies to error monitoring, data feeds, and even AI agent-to-agent communication.

Contrarian: What the Bulls Got Right

Some argue that the attack requires the developer to ask the agent to debug a Sentry issue. That's a specific workflow. It's not a fully automated exploit. The bulls claim that with proper user training and approval gates, the risk is manageable. They point to Tenet's own mitigation tool, agent-jackstop, which adds network whitelists, command approval, and credential protection. They say it's a configuration problem, not a fundamental flaw.

They are right about one thing: the attack is not inevitable. But they are wrong about the root cause. The issue is not the configuration. It's the trust model. The AI agent is designed to trust the data it receives from tools. That trust is exploited. The mitigation tools are band-aids. They reduce the blast radius, but they don't fix the architecture. The MCP protocol still treats data as instructions. The exploit will evolve. The content filter Sentry deployed can be bypassed with simple obfuscation. The game of cat and mouse has begun.

Illusion has a price tag; truth has none. The bull market tells you AI agents are the future. The truth is they are a security liability until the architecture is redesigned.

Takeaway: The Accountability Call

The transaction is permanent; the mistake is not. The attack on Sentry and MCP is not a one-off. It's a warning shot. The AI-Crypto convergence is accelerating. Projects are building AI agents for trading, governance, auditing, and smart contract deployment. They are integrating MCP without understanding the risk. The same attack chain can be used to inject malicious code into a DAO voting agent, a yield aggregator, or a cross-chain bridge.

Based on my own experience with the Terra/Luna autopsy, I know that complex financial engineering often masks fundamental flaws. The same applies here. The MCP protocol is elegant engineering. But it's built on a trust assumption that will be exploited repeatedly. The next time you see a project bragging about AI agent integration, ask one question: "What happens when the data source is compromised?" If the answer is not a detailed technical mitigation, walk away. The code compiles, but the reality bankrupts.

Market Prices

Coin Price 24h
BTC Bitcoin
$79,785.5 -0.06%
ETH Ethereum
$2,496.83 -1.44%
SOL Solana
$106.62 +2.35%
BNB BNB Chain
$709.3 -0.35%
XRP XRP Ledger
$1.43 -0.73%
DOGE Dogecoin
$0.0877 -1.10%
ADA Cardano
$0.2098 -2.46%
AVAX Avalanche
$7.43 -0.04%
DOT Polkadot
$0.8752 -1.49%
LINK Chainlink
$11.71 -1.21%

Fear & Greed

73

Greed

Market Sentiment

Event Calendar

{{年份}}
30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$79,785.5
1
Ethereum ETH
$2,496.83
1
Solana SOL
$106.62
1
BNB Chain BNB
$709.3
1
XRP Ledger XRP
$1.43
1
Dogecoin DOGE
$0.0877
1
Cardano ADA
$0.2098
1
Avalanche AVAX
$7.43
1
Polkadot DOT
$0.8752
1
Chainlink LINK
$11.71

🐋 Whale Tracker

🔵
0xcab3...d1f5
6h ago
Stake
26,784 SOL
🟢
0x7170...ba4b
1d ago
In
5,398 BNB
🔴
0x925b...6ed5
12m ago
Out
2,805,435 USDC

💡 Smart Money

0xd620...2548
Market Maker
+$3.1M
86%
0x1fb7...6fd5
Market Maker
+$2.3M
94%
0x5e55...85bc
Top DeFi Miner
+$3.7M
93%