OpenA2A Research: security research on AI agent infrastructure

OpenA2A
Research
Updated Aug 16, 2026

Security research on AI agent infrastructure. A continuous honey-agent fleet, monthly internet-wide exposure sweeps, and live indices. Every finding classified by Threat Matrix technique, every count published with its query.

8
reports published
900K+
honey-agent events, all time
243.6K
exposed AI services
Aug 16, 2026
latest report
Featured · State of AI Agent Security: The Identity Ceiling

Agent identity is self-asserted. Behaviour is the only signal that is not.

Behavioral Threat Report Issue 4. Agent identity is something a client says about itself. All three routes to an agent verdict in our classifier are declarations, and the one bucket that is not a declaration cannot exclude a model driving a real browser: of 6,665 agent-attributed events zero are verified, while 1,921 declared-crawler rows are, because crawlers publish an identity and agents have none to publish. Detection that survives an uncooperative client has to be behavioural. Also in this issue: the honey-fleet noise floor published layer by layer, six earlier readings re-measured with the queries that produced them, and an honest account of which surfaces are still not instrumented.

Read the report
224.9K
events in window
99%
targeted MCP
14%
return rate
14,588
unique fingerprints

All four measured over the window.

Live signalscontinuous measurement
See live indices

Exposure over time

MarAprMayJunJulAugSep243.6K2026-09-01

Exposed AI services, one point per month, each the latest sweep that month and shown on the day it was measured. Where a month holds more than one sweep the readings can differ by more than the internet moves between months, so the date is part of the figure. How a sweep is counted.

What's exposed

OpenClaw gateways192.5K79.0%
Agent tools29.0K11.9%
LLM endpoints20.0K8.2%
MCP servers2.0K0.8%
Agent infrastructure1170.0%
A2A endpoints320.0%

ARIAscout sweep of .

What attackers target

Model Context Protocol (MCP)222.7K99.0%
Agent-to-Agent (A2A) handshake1.1K0.5%
Context-read (other)1.0K0.4%
MCP resource read100.0%

Honey-agent events, .

Where attacks originate

US · United States132.3K58.8%
IE · Ireland29.2K13.0%
JP · Japan6.7K3.0%
GB · United Kingdom5.4K2.4%
CA · Canada4.8K2.2%

Top 5 of 105 countries observed, over the window.

Confirmed findings

162artifacts confirmed across 157 hosts
exposed .git/config repos115
agent instruction files31
credentials and private keys15
MCP tool manifests1

Content-verified ARIAscout Shodan probe, measured .

Passive Shodan-index probe, dedup’d by host (point-in-time). A floor, not directly comparable to the January 2026 active host probe.

Where payloads hide

hidden text15657.4%
HTML comment6222.8%
script literal269.6%
alt / aria text176.3%
meta tag62.2%
data attribute51.8%

All 272 active planted payloads across 224 sites. Placement is a single value per payload, so these six shares sum to the whole population. Census last ingested .

Scoped to payloads we still judge real. Over every row the crawler has ever recorded, script literals lead instead, because that placement loses the most rows to false-positive review.

Where planted payloads live

US · United States17363.6%
FR · France197.0%
CA · Canada186.6%
DE · Germany134.8%
DK · Denmark124.4%
RU · Russia82.9%
GB · United Kingdom51.8%
JP · Japan41.5%

Country of the site hosting the payload. Top 8 of 272. The remaining 20 span 16 more countries, and 1 address did not resolve. Census last ingested .

Not the same question as the panel above. Attacks reach us from cloud ranges. The pages carrying planted instructions are ordinary sites in 24 countries.

8 reports
behavioral threat report14 min read

State of AI Agent Security: The Identity Ceiling

Behavioral Threat Report Issue 4. Agent identity is something a client says about itself. All three routes to an agent verdict in our classifier are declarations, and the one bucket that is not a declaration cannot exclude a model driving a real browser: of 6,665 agent-attributed events zero are verified, while 1,921 declared-crawler rows are, because crawlers publish an identity and agents have none to publish. Detection that survives an uncooperative client has to be behavioural. Also in this issue: the honey-fleet noise floor published layer by layer, six earlier readings re-measured with the queries that produced them, and an honest account of which surfaces are still not instrumented.

behavioral threat report16 min read

State of AI Agent Security: Who Follows the Bait

Behavioral Threat Report Issue 3. Agent-vs-crawler attribution shipped this month: of the AgentPwn payload callbacks we could attribute, 1,985 were browsers and link prefetchers, 9 were LLM content crawlers, and 0 were autonomous LLM agents. It corrects the Issue 2 framing. Inside the honey-agent fleet, MCP drew 99% of events and 99.5% of sessions classified as automated scanners.

behavioral threat report15 min read

State of AI Agent Security: A Surface in Migration

Behavioral Threat Report Issue 2. In the 30-day window the Model Context Protocol drew 97.9% of honey-agent events, up from 75%. Exposure rose to 320,506 services with exposed Ollama up 225% and MLflow up 173%. 41% of unique attacker fingerprints returned. Reported on a corrected 30-day-window basis.

behavioral threat report15 min read

State of AI Agent Security: The Protocol Attackers Prefer

Inaugural Behavioral Threat Report. 206,571 honey-agent events across 9,037 unique attacker fingerprints over 30 days. The Model Context Protocol drew three of every four attacker events. 45% of unique attackers returned across multiple sessions. 343 wild injection-bait surfaces detected on the public web.

exposure sweep6 min read

Internet-Wide AI Exposure Sweep: April 2026

321,929 exposed AI services indexed by Shodan. 263,853 OpenClaw gateways on port 18789, 25,097 Streamlit apps, 25,036 Ollama instances identified by product signature. First sweep using product-based queries for higher-confidence identification.

ecosystem analysis8 min read

OASB Scanner Benchmark: accuracy figures withdrawn (the benign class was self-labeled)

Withdrawn 2026-08-09. This report published the HMA full pipeline at 82.9% F1 / 83.2% precision / 1.16% FPR against a corpus whose benign class was labeled by the scanner under test: 3,704 of 3,881 benign samples came from the rule "verdict=warning AND overall_score >= 70" as reported by HackMyAgent itself, so anything it would have flagged was excluded from the benign class by construction. Every metric that reads the benign class is a labeling artifact. Recall (82.6% on 270 fixtures we authored) is retained with disclosure. The corpus, taxonomy and the comparison with Holzbauer et al. are unaffected.

exposure sweep6 min read

Internet-Wide AI Exposure Sweep: March 2026

490,295 Shodan detections. ~140,000 verified exposed AI services after active HTTP probing. 3.5x inflation factor between passive scanning and confirmed findings.

exposure sweep7 min read

97,000 AI Agents Exposed

We scanned 97,013 internet-facing hosts for AI agent vulnerabilities. 14.4% had confirmed security issues. 1,190 had their system instructions publicly readable.