OpenA2A
Research
Updated Jul 22, 2026

Security research on AI agent infrastructure. A continuous honey-agent fleet, monthly internet-wide exposure sweeps, and live indices. Every finding classified by Threat Matrix technique, every count published with its query.

7
reports published
500K+
honey-agent events
204.9K
exposed AI services
Jul 22, 2026
latest report
Featured · State of AI Agent Security: Who Follows the Bait

The agents following our injections are mostly not agents.

Behavioral Threat Report Issue 3. Agent-vs-crawler attribution shipped this month: of the AgentPwn payload callbacks we could attribute, 1,985 were browsers and link prefetchers, 9 were LLM content crawlers, and 0 were autonomous LLM agents. It corrects the Issue 2 framing. Inside the honey-agent fleet, MCP drew 99% of events and 99.5% of sessions classified as automated scanners.

Read the report
99%
targeted MCP
14%
return rate
500K+
events since launch
14,588
unique fingerprints
Live signalscontinuous measurement
See live indices

Exposure over time

JanFebMarAprMayJunJul204.9K

Exposed AI services per monthly internet-wide sweep. Latest: 204.9K.

What's exposed

OpenClaw Gateways171.0K83.5%
Streamlit AI Apps22.4K10.9%
Ollama Instances5.1K2.5%
MLflow Tracking2.9K1.4%
MCP Streamable HTTP1.7K0.8%
Jupyter Notebooks1.4K0.7%

What attackers target

Model Context Protocol (MCP)222.7K99.0%
Agent-to-Agent (A2A) handshake1.1K0.5%
Context-read (other)1.0K0.4%
MCP resource read100.0%

Honey-agent events, June 22 to July 22, 2026 (30 days).

Where attacks originate

US · United States132.3K58.8%
IE · Ireland29.2K13.0%
JP · Japan6.7K3.0%
GB · United Kingdom5.4K2.4%
CA · Canada4.8K2.2%

Top 5 of 105 countries observed.

Confirmed findings

162artifacts confirmed across 157 hosts
exposed .git/config repos115
agent instruction files31
credentials and private keys15
MCP tool manifests1

Content-verified ARIAscout Shodan probe · June 2026.

Passive Shodan-index probe, dedup’d by host (point-in-time). A floor, not directly comparable to the January 2026 active host probe.

7 reports
behavioral threat report16 min read

State of AI Agent Security: Who Follows the Bait

Behavioral Threat Report Issue 3. Agent-vs-crawler attribution shipped this month: of the AgentPwn payload callbacks we could attribute, 1,985 were browsers and link prefetchers, 9 were LLM content crawlers, and 0 were autonomous LLM agents. It corrects the Issue 2 framing. Inside the honey-agent fleet, MCP drew 99% of events and 99.5% of sessions classified as automated scanners.

behavioral threat report15 min read

State of AI Agent Security: A Surface in Migration

Behavioral Threat Report Issue 2. In the 30-day window the Model Context Protocol drew 97.9% of honey-agent events, up from 75%. Exposure rose to 320,506 services with exposed Ollama up 225% and MLflow up 173%. 41% of unique attacker fingerprints returned. Reported on a corrected 30-day-window basis.

behavioral threat report15 min read

State of AI Agent Security: The Protocol Attackers Prefer

Inaugural Behavioral Threat Report. 206,571 honey-agent events across 9,037 unique attacker fingerprints over 30 days. The Model Context Protocol drew three of every four attacker events. 45% of unique attackers returned across multiple sessions. 343 wild injection-bait surfaces detected on the public web.

exposure sweep6 min read

Internet-Wide AI Exposure Sweep: April 2026

321,929 exposed AI services indexed by Shodan. 263,853 OpenClaw gateways on port 18789, 25,097 Streamlit apps, 25,036 Ollama instances identified by product signature. First sweep using product-based queries for higher-confidence identification.

ecosystem analysis8 min read

OASB Scanner Benchmark: detection on a ground-truth labeled corpus

The HMA full pipeline scores 82.9% F1 (82.6% recall, 83.2% precision, 1.16% FPR) on 4,245 labeled samples across 9 attack categories. The verdict counts attack findings and excludes posture findings (missing defenses, and wildcard tool access that thousands of benign MCP servers also declare). DVAA full-repo detection 29.1%. Comparison with 9 industry scanners from Holzbauer et al. The earlier 89.2% and 82.1% F1 figures are withdrawn.

exposure sweep6 min read

Internet-Wide AI Exposure Sweep: March 2026

490,295 Shodan detections. ~140,000 verified exposed AI services after active HTTP probing. 3.5x inflation factor between passive scanning and confirmed findings.

exposure sweep7 min read

97,000 AI Agents Exposed

We scanned 97,013 internet-facing hosts for AI agent vulnerabilities. 14.4% had confirmed security issues. 1,190 had their system instructions publicly readable.