OpenA2A Research: security research on AI agent infrastructure

OpenA2A
Research
Updated Sep 17, 2026

Security research on AI agent infrastructure. A continuous honey-agent fleet, monthly internet-wide exposure sweeps, and live indices. Every finding classified by Threat Matrix technique, every count published with its query.

439.1K
TrapMyAgent events, 30 days
0 of 2,437
AgentPwn callbacks from declared autonomous agents, 30 days
243.6K
exposed AI services
2.3M+
requests logged by the OpenA2A honeypot network, all time
Featured · State of AI Agent Security: Volume Without Declared Agents

TrapMyAgent saw twice the traffic from fewer clients. Of 2,437 attributed callbacks on the AgentPwn honeypot pages, none came from a client declaring itself an autonomous agent.

Behavioral Threat Report Issue 5. TrapMyAgent recorded 439,114 events in the 30 days to September 17, about twice the previous comparable window, from 8,776 distinct fingerprints, fewer than before. With attribution covering every callback in the window, 0 of 2,437 attributed AgentPwn callbacks came from a client declaring itself an autonomous agent. Agent-to-Agent handshakes on TrapMyAgent rose about 14 times while A2A tasks stayed at 2. Exposed OpenClaw gateways and MCP servers grew on the month; the 243,615 exposed AI services ARIAscout counted are published without a trend on the total.

Read the report
439.1K
events in window
96.1%
targeted MCP
27%
return rate
8,776
unique fingerprints

All four measured over the window.

Live signalscontinuous measurement
See live indices

Exposure over time

MarAprMayJunJulAugSep243.6K2026-09-01

Exposed AI services, one point per month, each the latest sweep that month and shown on the day it was measured. Where a month holds more than one sweep the readings can differ by more than the internet moves between months, so the date is part of the figure. How a sweep is counted.

What's exposed

OpenClaw gateways192.5K79.0%
Agent tools29.0K11.9%
LLM endpoints20.0K8.2%
MCP servers2.0K0.8%
Agent infrastructure1170.0%
A2A endpoints320.0%

ARIAscout sweep of .

What attackers target

Model Context Protocol (MCP) connection422.0K96.1%
Agent-to-Agent (A2A) handshake15.7K3.6%
Context read (other)1.4K0.3%
MCP resource read, file read, MCP tool call, A2A task610.0%

Honey-agent events, .

Where attacks originate

US · United States264.4K60.2%
BG · Bulgaria26.1K5.9%
DE · Germany20.9K4.8%
IE · Ireland9.2K2.1%
CA · Canada7.9K1.8%

Top 5 of 127 countries observed, over the window.

9 reports
behavioral threat report8 min read

State of AI Agent Security: Volume Without Declared Agents

Behavioral Threat Report Issue 5. TrapMyAgent recorded 439,114 events in the 30 days to September 17, about twice the previous comparable window, from 8,776 distinct fingerprints, fewer than before. With attribution covering every callback in the window, 0 of 2,437 attributed AgentPwn callbacks came from a client declaring itself an autonomous agent. Agent-to-Agent handshakes on TrapMyAgent rose about 14 times while A2A tasks stayed at 2. Exposed OpenClaw gateways and MCP servers grew on the month; the 243,615 exposed AI services ARIAscout counted are published without a trend on the total.

behavioral threat report14 min read

State of AI Agent Security: The Identity Ceiling

Behavioral Threat Report Issue 4. Agent identity is something a client says about itself. All three routes to an agent verdict in our classifier are declarations, and the one bucket that is not a declaration cannot exclude a model driving a real browser: of 6,665 agent-attributed events zero are verified, while 1,921 declared-crawler rows are, because crawlers publish an identity and agents have none to publish. Detection that survives an uncooperative client has to be behavioural. Also in this issue: the honey-fleet noise floor published layer by layer, six earlier readings re-measured with the queries that produced them, and an honest account of which surfaces are still not instrumented.

behavioral threat report16 min read

State of AI Agent Security: Who Follows the Bait

Behavioral Threat Report Issue 3. Agent-vs-crawler attribution shipped this month: of the AgentPwn payload callbacks we could attribute, 1,985 were browsers and link prefetchers, 9 were LLM content crawlers, and 0 were autonomous LLM agents. It corrects the Issue 2 framing. Inside the honey-agent fleet, MCP drew 99% of events and 99.5% of sessions classified as automated scanners.

behavioral threat report15 min read

State of AI Agent Security: A Surface in Migration

Behavioral Threat Report Issue 2. In the 30-day window the Model Context Protocol drew 97.9% of honey-agent events, up from 75%. Exposure rose to 320,506 services with exposed Ollama up 225% and MLflow up 173%. 41% of unique attacker fingerprints returned. Reported on a corrected 30-day-window basis.

behavioral threat report15 min read

State of AI Agent Security: The Protocol Attackers Prefer

Inaugural Behavioral Threat Report. 206,571 honey-agent events across 9,037 unique attacker fingerprints over 30 days. The Model Context Protocol drew three of every four attacker events. 45% of unique attackers returned across multiple sessions. 343 wild injection-bait surfaces detected on the public web.

exposure sweep6 min read

Internet-Wide AI Exposure Sweep: April 2026

321,929 exposed AI services indexed by Shodan. 263,853 OpenClaw gateways on port 18789, 25,097 Streamlit apps, 25,036 Ollama instances identified by product signature. First sweep using product-based queries for higher-confidence identification.

ecosystem analysis8 min read

OASB Scanner Benchmark: accuracy figures withdrawn (the benign class was self-labeled)

Withdrawn 2026-08-09. This report published the HMA full pipeline at 82.9% F1 / 83.2% precision / 1.16% FPR against a corpus whose benign class was labeled by the scanner under test: 3,704 of 3,881 benign samples came from the rule "verdict=warning AND overall_score >= 70" as reported by HackMyAgent itself, so anything it would have flagged was excluded from the benign class by construction. Every metric that reads the benign class is a labeling artifact. Recall (82.6% on 270 fixtures we authored) is retained with disclosure. The corpus, taxonomy and the comparison with Holzbauer et al. are unaffected.

exposure sweep6 min read

Internet-Wide AI Exposure Sweep: March 2026

490,295 Shodan detections. ~140,000 verified exposed AI services after active HTTP probing. 3.5x inflation factor between passive scanning and confirmed findings.

exposure sweep7 min read

97,000 AI Agents Exposed

We scanned 97,013 internet-facing hosts for AI agent vulnerabilities. 14.4% had confirmed security issues. 1,190 had their system instructions publicly readable.