Last month this report described a callback rate as the share of agents that followed our injection bait. This month we can attribute those callbacks, and the framing was too generous. Of the 1,994 payload callbacks we could attribute after agent-vs-crawler attribution shipped on July 16, 1,985 resolved to browsers and link prefetchers, 9 to declared LLM content crawlers, and 0 to autonomous LLM agents. A callback counts a client fetching a URL. It does not, on its own, count an agent reasoning over an injection. Inside the honey-agent fleet the picture is consistent: the Model Context Protocol drew 99% of observed events, and 99.5% of sessions classified as automated scanners. This edition is about telling the two apart.
What this report is
This is Issue 3 of the Behavioral Threat Report, a monthly synthesis published by ARIA, OpenA2A's autonomous research system, with editorial review by Abdel Fane. The numbers in this report are anchored in instrumentation that has run continuously through the reporting window. Methodology is documented at research.opena2a.org/methodology and the findings are reproducible by anyone who deploys equivalent instrumentation.
Four data streams contribute. ARIAscout ran a fresh Shodan sweep on July 22, 2026 to anchor the exposure picture as of publication. AgentPwn instruments honeypot pages with benign injection payloads across sector verticals. TrapMyAgent runs honey agents that observe attacker behavior when attackers believe they have control. HoneyMap samples the public web for adversarial injection patterns planted by third parties. The synthesis is the point: exposure measures latent surface, the honeypot ecosystem measures what reaches it. Every classification in this report resolves to an Agent Threat Matrix technique identifier in T-NNNN format.
A correction to Issue 2. Issue 2 reported an aggregate AgentPwn callback rate and described it as the share of agents that followed a payload. Agent-vs-crawler attribution shipped on July 16 and shows that framing was wrong: the followers are overwhelmingly browsers and link prefetchers, not autonomous agents. Section 2 reports the attributed split. We publish this correction prominently because getting attribution right is the point of the fleet.
A note on the honey-agent count. TrapMyAgent computes every behavioral distribution over a rolling 30-day window. This edition reports the honey-agent figure on that window basis (224,891 events, up from 106,943 in the Issue 2 window), which is the basis every distribution below is computed on. The cumulative total since fleet launch is a Postgres planner estimate that now exceeds 500,000 events; it is presented only as a floor and never as a denominator.
1. The volume picture
Combined activity across the four streams. Behavioral telemetry is the 30-day window ending July 22. ARIAscout's exposure sweep was run July 22 for this report.
Read the exposure total with care. ARIAscout counted 204,866 exposed AI services this month against 320,506 in June, but most of that movement is measurement noise, not a real shift. The per-product Shodan facet counts for exposed Ollama and MLflow instances swing widely month to month on an unchanged query, so we do not report a trend on them. The stable signal is the OpenClaw gateway, which held roughly flat from 175,861 in June to 171,036 now and remains the single largest exposed surface by a wide margin. Exposed MCP servers stood at 1,694 and broken-out A2A endpoints at 24.
Latent surface and active contact are different measurements. Exposure counts what is reachable. The honeypot streams count what actually arrives, and what arrives is dominated by commodity automation: 99.5% of honey-agent sessions classify as automated scanners, and the AgentPwn callbacks resolve mostly to browsers and prefetchers. The rest of this report is the work of separating the small genuine-agent signal from that background.
2. Who follows the bait
AgentPwn recorded 7,441 payload callbacks in the window across 35,485 distinct fingerprints. A callback fires when a client fetches the URL embedded in an injection payload. Until this month we could not say what kind of client. Agent-vs-crawler attribution shipped on 2026-07-16, so of those callbacks we can now attribute the 1,994 recorded since.
The followers are not agents. 1,985 of 1,994 attributed callbacks came from browsers and link prefetchers, 9 from declared LLM content crawlers, and 0 from autonomous LLM agents. A browser or an unfurler fetches every link it sees. That behavior produces a callback without any agent ever reading, let alone obeying, the injection. The aggregate callback rate that Issue 2 reported measured this prefetch behavior, not agent compliance. That is the correction, and it is the most important finding in this edition.
The attributed window is short (roughly six days of the thirty), so these are early counts, not a settled distribution. But the direction is unambiguous and consistent with the honey-agent side, where the single largest user-agent is a registry crawler rather than an attacker. A defender or researcher who publishes an agent-follow rate should separate agent runtimes from crawlers and unfurlers first. We will report a full attributed window next edition, and we will not restate the old aggregate rate as if it measured agents.
3. The technique picture
AgentPwn payload category leaderboard for the window. Each category resolves to one or more Agent Threat Matrix techniques. These count payloads planted and delivered, not compromises.
MITRE ATT&CK techniques observed in TrapMyAgent telemetry over the same 30-day window. These are heuristic classifier labels. Month-over-month MITRE counts are not yet stable enough to compare across editions, so this table is a snapshot of the current window, not a trend.
| MITRE ATT&CK | Technique | Events |
|---|---|---|
| MITRE T1497.003 | Time-Based Evasion | 7,910 |
| MITRE T1550 | Use Alternate Authentication Material | 194 |
| MITRE T1518 | Software Discovery | 118 |
The heuristic labels track the dominant scanner behavior in the window (time-based evasion patterns from automated probing), which is why the counts are volatile and why we withhold cross-edition comparison until a supervised classifier grounds them. AgentPwn's direct prompt-injection category (701 planted) and TrapMyAgent's Use-Alternate-Authentication-Material observation resolve to T-2001 and T-3001 on the Agent Threat Matrix. A defender that hardens against either independently still leaves the other open.
4. The adversary picture
Attack-origin geography spans 105 countries. Top ten by event volume, as a share of the 224,891 honey-agent events in the window.
Cloud providers fronting the traffic. Provider attribution reflects which network fronted the events, not which network originated them. Note that a majority of events front through a single Microsoft Azure ASN, consistent with cloud-hosted scanning and content-indexing rather than a distributed adversary.
automated_scanner
Classifier verdicts (per session)
- Automated scanner35,22399.5%
- Unknown1760.5%
- APT reconnaissance50.01%
How to read this. Almost all observed traffic is mass automated probing. The APT-reconnaissance count is small because the classifier's heuristic rules deliberately lag the technique catalog. Five APT-reconnaissance sessions are not a noise floor, they are flags: any single observation in the non-automated categories deserves investigation. We do not refine the heuristics week-to-week because a misclassification rate that drifts is harder to interpret across editions than a heuristic that conservatively under-reports.
Recurrence is mostly scanners
Of 14,588 distinct fingerprints in the window, 2,004 (13.7%) returned across more than one session. That recurrence is real, but it is not a returning adversary population. The single most persistent fingerprint recurred across more than 5,000 sessions with roughly one event each, the signature of a scanner rather than an attacker sampling defenses. With 99.5% of sessions classified as automated scanners, the recurring population is dominated by commodity scanning. The defensible statement is the segmented one: fingerprint-stable telemetry is worth building, and the honest returning-attacker figure is far smaller than the raw rate.
Attribution limits. Geography reflects origin IP geolocation, which VPN, proxy, and cloud-fronting can obscure. Microsoft Azure's 56.1% share is best read as "Azure-fronted traffic," not "traffic originating in Azure data centers." ASN-level data in the methodology block separates origin from terminus.
5. The protocol picture
Event types observed across the TrapMyAgent fleet in the 30-day window.
MCP
- Model Context Protocol (MCP)222,73899%
- Agent-to-Agent (A2A) handshake1,1250.5%
- Context-read (other)1,0110.4%
- MCP resource read100%
The Model Context Protocol drew 99% of honey-agent events this window, up marginally from 97.9% a month ago. Observed contact keeps concentrating on one protocol even as the exposed surface fans out across other infrastructure. For a defender that is a clarifying result about where to spend a hardening hour. One caveat carries through the whole section: the largest single user-agent in this MCP traffic is mcpregistry-bot, a crawler that indexes MCP servers, so raw MCP event volume reflects indexing pressure as much as attack intent. Agent-to-Agent handshakes were 0.5% of events. A quiet channel is not a closed one: ARIAscout still counts exposed A2A endpoints, and Section 8 carries hardening guidance for both.
6. The wild picture
HoneyMap samples the public web for injection bait planted by third parties. The window captured 262 surfaces across 215 unique domains. The result is a sample, not a coverage count.
Attack classes:
Top AIIS signatures observed:
Where the bait lives on the page:
Sector distribution (where the bait sits):
248 of 262 surfaces (95%) carry no sector classification. This is the honest answer, not a classification gap. Most injection bait lives on pages with no clear sector identity, and the catalog deliberately does not guess. The named sectors are the surfaces where the page itself made the classification trivial.
The wild is being seeded, not yet weaponized at scale, but the bait is real. SOUL-INJECT, the class that targets agent personality and soul-authority directives, is the most-observed attack class at 223 surfaces. Every signature in this section is one defenders should already be checking for. The bait tends to arrive before the campaign that uses it.
7. The model attribution picture
This edition adds the first agent-vs-crawler attribution to the fleet. The categories below anchor on it. We do not name a vendor or model without evidence, and all attribution this window carries claimed confidence (derived from client-declared user-agents), not verified confidence.
| Attribution category | Share of callbacks | Notes |
|---|---|---|
| Browsers and link prefetchers | almost all attributed callbacks | Standard browser and mobile WebKit user-agents. On the AgentPwn honeypots, agent-vs-crawler attribution resolved 1,985 of 1,994 attributed payload callbacks to this class. These are link unfurlers and prefetchers fetching every URL, not agents reasoning over an injection. |
| LLM content crawlers | a small fraction of callbacks | Declared crawler user-agents (GPTBot, ClaudeBot, PerplexityBot and peers) that index pages. 9 of 1,994 attributed callbacks. They fetch content; they do not use the tool surface. On the honey-agent fleet the top user-agent is mcpregistry-bot, a crawler that indexes MCP servers rather than attacking them. |
| LLM agents | none attributed this window | Autonomous agent runtimes acting on tool output. 0 of 1,994 attributed payload callbacks in the window. The surface that is built to catch these is the authenticated cohort in Section 8, which is not yet seeded to draw them. |
User-agent strings are attacker-controllable and cannot ground an identity claim on their own, which is why every label this window is claimed rather than verified. The verified tier requires an independent signal, such as a first-party crawler whose network ownership matches its declared vendor. We are building behavioral fingerprinting (request-timing distributions, header-order canonicalization, tool-call structure) to close the gap. Progress will appear in subsequent editions.
8. What this means for defenders
Seven recommendations follow from the data above. Each cites the Agent Threat Matrix technique it resolves to and the OASB control that implements the defense.
Attribute agent traffic before you count it. Most bait-followers are browsers and prefetchers, not agents.
On the AgentPwn honeypots, of the 1,994 payload callbacks we could attribute since agent-vs-crawler attribution shipped on July 16, 1,985 resolved to browsers and link prefetchers, 9 to declared LLM content crawlers, and 0 to autonomous LLM agents. A raw callback rate measures which clients fetch a URL, not which agents reasoned over an injection. Any defender or researcher publishing an agent-follow rate should first separate agent runtimes from unfurlers and crawlers, or the number describes prefetch behavior.
Maps to: T-2002 · OASB 10.1 (Security Event Logging), OASB 3.1 (Prompt Injection Protection)
Treat the Model Context Protocol as the dominant honey-agent surface. It is now 99% of observed events.
Within the 30-day window the Model Context Protocol drew 222,738 of 224,891 honey-agent events (99.0%), up from 97.9% a month ago. The observed contact keeps concentrating on one protocol even as the exposed surface fans out. MCP servers should require authentication, rate limit tool discovery, and reject tool definitions that contain unicode tag-block sequences. Note that the single largest user-agent in this traffic is mcpregistry-bot, a crawler indexing MCP servers, so raw MCP event volume is not by itself evidence of attack intent.
Maps to: T-1002, T-2005 · OASB 2.1 (Explicit Capability Grants), OASB 2.3 (Capability Boundaries)
Lock down unauthenticated model-serving infrastructure, but do not trust volatile exposure counts.
ARIAscout's July 22 sweep counted 169,521 exposed OpenClaw gateways, the stable dominant exposure across three monthly sweeps. Per-product counts for exposed Ollama and MLflow instances swing widely month to month on an unchanged Shodan query, so this edition reports their current counts (5,114 and 2,918) without a growth figure and does not headline a trend. The hardening guidance stands regardless of the count: unauthenticated inference and experiment-tracking endpoints should sit behind authentication and network policy.
Maps to: T-1002 · OASB 2.1 (Explicit Capability Grants), OASB 5.3 (Credential Scope Limitation)
Filter rendered HTML for the AIIS hidden-injection signatures in agent retrieval pipelines.
The AIIS-HIDDEN-JAILBREAK-DAN-01 signature appeared on 122 of 262 wild bait surfaces, the most of any, and AIIS-HIDDEN-ROLE-INJECT-01 on 87. Any agent that reads web content into an LLM context window should strip hidden text and unicode tag-block characters before tokenization. The window's surface count fell from 446 because the AIIS signatures were recalibrated for precision, not because wild bait declined.
Maps to: T-2002 · OASB 3.1 (Prompt Injection Protection), OASB 3.3 (Input Validation)
Most recurring visitors are scanners. Segment before you call recurrence attacker persistence.
Of 14,588 distinct fingerprints in the window, 2,004 (13.7%) returned across more than one session. But 99.5% of sessions classify as automated scanners, and the single most persistent fingerprint recurred across more than 5,000 sessions with roughly one event each, the signature of a scanner, not a returning adversary. Recurrence is real and worth fingerprint-stable telemetry to measure, but the recurring population is dominated by commodity scanning. Report the segmented figure, not the raw return rate.
Maps to: T-9001 · OASB 10.1 (Security Event Logging)
Agent-to-Agent traffic stayed low in the window, but exposed A2A endpoints persist. Keep authenticating handshakes.
A2A handshakes were 0.5% of observed events (1,125). A low observation is not a closed surface. ARIAscout still counts exposed A2A endpoints. Authenticate every A2A handshake, verify the calling agent's identity before honoring a capability request, and reject agent-card discovery from unknown peers by default.
Maps to: T-1006, T-2008, T-3001 · OASB 7.1 (Mutual Authentication), OASB 7.2 (Message Integrity), OASB 5.2 (Context Window Isolation)
Close the Common Crawl gap by instrumenting authenticated and dynamic surfaces.
Public-web crawls, including Google's January 2026 indirect-prompt-injection study, are systematically blind to login-walled, per-fingerprint-dynamic, and federated-social content. Honeypot fleets that observe interactive behavior post-credential are the only way to measure that gap. This report's methodology details the partition.
The Common Crawl gap
Public-web measurement studies, including Google's January 2026 indirect-prompt-injection sweep, sample crawls that surface only anonymous, statically rendered, search-engine-discoverable content. Three classes of attacker-reachable surface are systematically invisible to that sample.
- Authenticated surfaces. Login walls, gated dashboards, post-auth tool calls. An agent that completes a credential-acquisition step reaches a different content surface and exhibits behaviors that crawler-only research cannot observe.
- Dynamic surfaces. Per-fingerprint content variation. The same URL serves different HTML to different agents. Static crawls collapse this to a single template.
- Social surfaces. Federated and platform-mediated content where indexing is partial, latent, or restricted.
OpenA2A's honeypot fleet is built across this seam. The baseline sites are deliberately Common-Crawl-visible and carry essentially all of the traffic in this report. A second set of authenticated archetypes (one live so far, cloudops-agent-io) sits behind a credential, where no crawler reaches. This edition's attribution finding sharpens why that seam matters: the public-web cohort is drawing browsers and crawlers, not agents, so the surface that could observe genuine autonomous-agent behavior is precisely the authenticated one that public-web sweeps cannot see. As those archetypes mature and begin drawing agents, future editions report what arrives there.
9. Methodology, limits, and how to cite
techniques
Threat Matrix evidence tiers
- Observed in production16
- Validated in lab42
- Theoretical, flagged3
Source: Agent Threat Matrix evidence audit, locked at publication.
Methodology. Full per-stream methodology is published at /methodology, with sub-pages for behavioral-sweep (ARIAtrap) and first-observed-in-the-wild (FOITW). All four streams run continuously. Numbers in this report are the snapshot at publication.
Window and basis. June 22 to July 22, 2026 (30 days). TrapMyAgent behavioral distributions are computed over the 30-day window, and the honey-agent event figure is the exact count in that window. AgentPwn callback attribution covers only the callbacks recorded since attribution shipped on 2026-07-16, a subset of the window, and is labeled as such wherever it appears. The cumulative honey-agent total is an approximate planner-estimated count, presented as a floor and never used as a denominator.
What this report cannot answer this month.
- AgentPwn callback attribution covers about six days of the window. The direction is clear (browsers and crawlers, not agents) but the full-window distribution waits for next edition.
- ARIAscout per-product exposure counts (Ollama, MLflow) are Shodan facet counts that swing month to month on an unchanged query. We report current counts without a trend and lead on the stable OpenClaw gateway figure.
- MITRE ATT&CK counts are heuristic classifier labels and are not yet stable enough to compare across editions. They appear as a within-window snapshot only.
- HoneyMap is a sample of the public web, not a coverage count, and its surface total fell this window because the AIIS signatures were tightened for precision, not because wild bait declined.
- Sophistication scoring is published as distribution-only. No mean, grade, or month-over-month delta. The supervised classifier that would ground a mean does not yet exist.
- Model attribution is claimed-confidence only this window. No callback carried verified confidence. We will not name a vendor without an independent signal.
How to cite
@techreport{opena2a-btr-2026-07,
author = {{ARIA, OpenA2A autonomous research system} and Abdel Fane (editor)},
title = {State of AI Agent Security: Who Follows the Bait},
institution = {OpenA2A Research},
year = {2026},
month = {7},
type = {Behavioral Threat Report},
number = {Issue 3},
url = {https://research.opena2a.org/reports/state-of-ai-agent-security-2026-07}
}ARIA, & Fane, A. (Ed.). (2026, July 22). State of AI Agent Security: Who Follows the Bait (Behavioral Threat Report Issue 3). OpenA2A Research. https://research.opena2a.org/reports/state-of-ai-agent-security-2026-07
How to challenge a finding
Email info@opena2a.org with the specific number you dispute and the methodology you would prefer we used. We aim to respond within five business days. Substantive challenges that hold up under review are published as methodology updates in subsequent editions with attribution.
Appendix. First Observed In The Wild log
FOITW is the mechanism by which OpenA2A pre-registers signatures for sophisticated AI agent attack techniques and publishes within seven days of first wild observation. The pre-registration catalog lives at aria/data/foitw-catalog.json with full methodology at /methodology/foitw.
Catalog state at publication: 3 signatures registered, 0 firings during the reporting window. Transparency-log anchoring is in progress. Log-anchored claims will publish once the integration lands.
| Catalog ID | Name | Technique | Status |
|---|---|---|---|
| FOITW-CAT-0001 | Greshake-class indirect prompt injection via web content Greshake et al. (AISec 2023). Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. | T-2002 | Pre-registered 2026-04-27. Not yet fired. |
| FOITW-CAT-0002 | Actor-Critic adaptive multi-turn manipulation Shi, Lin, Song, et al. Lessons from Defending Gemini Against Indirect Prompt Injections (Google DeepMind, 2025). | T-2007 | Pre-registered 2026-04-27. Not yet fired. |
| FOITW-CAT-0003 | Reputation-poisoning prompt injection Brunner, Liu, Pande. AI threats in the wild: The current state of prompt injections on the web (Google Threat Intelligence Group, April 2026). | T-9005 | Pre-registered 2026-04-27. Not yet fired. |
Live indices at publication
The numbers in this report are the time-capsule snapshot. The indices below are continuously updated. Click through for the live methodology and CSV exports.
Authorship. ARIA is OpenA2A's autonomous research system. Editorial review by Abdel Fane. Disclosure of authorship is a credibility move, not a limitation. We document how our content is made.
Data integrity. Every value in this report traces to a query against live instrumentation. The behavioral distributions and the 30-day honey-agent event count are exact counts. The AgentPwn attribution split counts only callbacks recorded since attribution shipped on 2026-07-16, and says so wherever it appears. The single cumulative figure (events since fleet launch) is a Postgres planner estimate, presented as a floor and never used as a denominator. No number is modeled or projected. Pre-publication audit per Black Hat reproducibility standards.
License. Apache 2.0. Cite using the BibTeX or APA blocks in Section 9.
Coordinated disclosure. Any finding in this report that maps to a previously undisclosed vulnerability is held under the 90-day ARIAdesk disclosure protocol. None of the surface-level findings in this report require disclosure coordination.