OpenA2A Research: security research on AI agent infrastructure
Security research on AI agent infrastructure. A continuous honey-agent fleet, monthly internet-wide exposure sweeps, and live indices. Every finding classified by Threat Matrix technique, every count published with its query.
TrapMyAgent saw twice the traffic from fewer clients. Of 2,437 attributed callbacks on the AgentPwn honeypot pages, none came from a client declaring itself an autonomous agent.
Behavioral Threat Report Issue 5. TrapMyAgent recorded 439,114 events in the 30 days to September 17, about twice the previous comparable window, from 8,776 distinct fingerprints, fewer than before. With attribution covering every callback in the window, 0 of 2,437 attributed AgentPwn callbacks came from a client declaring itself an autonomous agent. Agent-to-Agent handshakes on TrapMyAgent rose about 14 times while A2A tasks stayed at 2. Exposed OpenClaw gateways and MCP servers grew on the month; the 243,615 exposed AI services ARIAscout counted are published without a trend on the total.
All four measured over the window.
Exposure over time
Exposed AI services, one point per month, each the latest sweep that month and shown on the day it was measured. Where a month holds more than one sweep the readings can differ by more than the internet moves between months, so the date is part of the figure. How a sweep is counted.
What's exposed
ARIAscout sweep of .
What attackers target
Honey-agent events, .
Where attacks originate
Top 5 of 127 countries observed, over the window.