Agentjacking at DEF CON 34: When Your AI Coding Assistant Becomes a Credential Extraction Tool

0xCobie Learn

I was sitting in the DEF CON 34 AI village when a researcher from Tenet Security demonstrated something that made the room fall silent. He showed how a single HTTP POST to a public Sentry DSN could turn a developer's AI coding assistant into a credential-stealing tool. This wasn't a theoretical attack crafted in a lab—it had an 85% success rate in controlled tests across 100+ organizations. The audience, a mix of security engineers and AI developers, collectively realized that the trust we place in AI agents to read external data sources is a trust we never formally verified.

To understand the attack, you need to understand two pieces of infrastructure that most developers take for granted. Sentry is an error monitoring platform that collects crash reports from applications. Its Data Source Name (DSN) is a public identifier that allows any service to send error events to a specific project. By design, the Sentry ingest endpoint accepts any HTTP POST containing a valid DSN—no authentication, no signature verification. This is intentional: error reporting should be frictionless. The MCP (Model Context Protocol) is an Anthropic-led open standard that allows AI agents to connect to external tools and data sources. Cursor and Claude Code, two of the most popular AI coding agents, use MCP to query Sentry for recent issues, read stack traces, and even suggest fixes based on the error context.

Here is the attack chain in six steps. First, an attacker scans public repositories, documentation, or even source code comments for exposed Sentry DSNs. The report identified 2,388 organizations with publicly discoverable DSNs, including 71 in the Tranco top 1 million websites and roughly 27% of Fortune 1000 companies exposed through Cloudflare's MCP integration. Second, the attacker crafts a malicious error event: a fake crash report containing a markdown-formatted “fix suggestion” that includes a command to install a malicious npm package. Third, the attacker sends this event via a simple POST to the Sentry ingest endpoint. Fourth, a developer on the victim team encounters an unrelated error, opens their AI coding assistant, and asks it to “look at the latest Sentry issues and fix them.” Fifth, the agent queries Sentry via MCP, fetches the malicious error, and—because the model cannot distinguish between data and instruction—interprets the markdown as a legitimate repair command. Sixth, the agent executes npm install on the developer's machine, which then exfiltrates credentials: AWS keys, GitHub OAuth tokens, npm registry tokens, and Docker registry credentials.

The core insight is not about Sentry or MCP individually—it is about the combinatorial architecture failure. Neither Sentry's unauthenticated endpoint nor MCP's data ingestion is a vulnerability on its own. The gap appears only when they are combined and when the AI agent lacks a semantic boundary between data and instruction. Based on my experience auditing smart contracts during the 2017 ICO boom, I have seen this pattern before: two secure systems create an insecure intersection because no one defined the trust boundary between them. In DeFi, it was the combination of flash loans and price oracle manipulations. Here, it is the combination of unauthenticated error feeds and trustful AI agents. The attack is a specific variant of indirect prompt injection, but the real novelty is that it exploits the operational workflow of developers who have come to rely on AI to automate debugging.

The industry response so far has been reactive and incomplete. Sentry deployed a content filter that blocks specific payload strings—essentially a string-level blacklist that can be trivially bypassed with base64 encoding or alternative phrasing. Tenet released an open-source tool called agent-jackstop that hardens the agent’s runtime environment: network egress whitelists, command execution approval, subprocess-level credential isolation, and treating all tool output as untrusted data. These are good practices, but they do not solve the root cause. The root cause is that the AI agent’s architecture has no mechanism to distinguish between “data” and “instruction” at the semantic level. Any external data source that the agent trusts can be weaponized. The content filter and the runtime hardening are band-aids, not cures.

Here is the contrarian angle: the attack is not as universal as it sounds. The 85% success rate came from a controlled test where the researcher simulated a developer explicitly asking the agent to fix a Sentry issue. In real-world scenarios, the attack requires a specific trigger—the developer must initiate a debugging session and ask the agent to consult Sentry. If the developer never asks, the agent never reads the malicious event. The attack surface is narrower than the headline suggests. Moreover, the emphasis on Sentry may be overblown. The real vulnerability is in the AI agent’s trust model, not in Sentry. Any tool that an agent can read—Jira, GitHub Issues, Slack logs, even a public pastebin—could be used as an injection vector. The attack is a symptom of a deeper issue: we are building agents that can read anything, but we are not building agents that can question what they read.

Listening to the silence between market cycles, I see this as a necessary safety brake on the adoption of AI coding agents. The bull market in AI tools has been driven by a narrative of productivity gains—write code faster, debug automatically, ship more features. But security teams are now paying attention. In the crypto space, where developers hold private keys, exchange API tokens, and deploy contracts directly from their machines, the consequences of credential theft are catastrophic. A stolen AWS key can lead to a drained cloud account; a stolen GitHub token can lead to a compromised repository with malicious code pushed to production. The event will likely slow down enterprise adoption of AI coding agents until proper guardrails are in place. It will also accelerate the emergence of a new security category: Agent Supply Chain Security. We will see MCP security gateways that validate and sanitize tool outputs, model-level training that treats all external data as untrusted, and insurance products that cover AI-induced credential losses.

The takeaway is forward-looking: the next time you see a shiny new AI coding assistant, remember that its trust in external data sources is its Achilles' heel. The industry is rushing to build agents that can read anything, but we are not building agents that can question what they read. Until we solve the semantic boundary between data and instruction, every AI agent is a potential vector for credential theft. The silence between market cycles is where we must build these safeguards. The question is not whether the attack will happen again—it will—but whether we will invest in the architectural fixes before the damage becomes systemic.

Market Prices

BTC Bitcoin
$75,777.4 -0.87%
ETH Ethereum
$2,393.99 -1.51%
SOL Solana
$97.24 -2.28%
BNB BNB Chain
$711.7 -1.07%
XRP XRP Ledger
$1.27 -8.99%
DOGE Dogecoin
$0.0792 -3.37%
ADA Cardano
$0.1919 -5.19%
AVAX Avalanche
$7.25 -2.70%
DOT Polkadot
$0.9768 -0.95%
LINK Chainlink
$10.73 -5.10%

Fear & Greed

51

Neutral

Market Sentiment

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

18
03
unlock Sui Token Unlock

Team and early investor shares released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Market Cap

All →
1
Bitcoin
BTC
$75,777.4
1
Ethereum
ETH
$2,393.99
1
Solana
SOL
$97.24
1
BNB Chain
BNB
$711.7
1
XRP Ledger
XRP
$1.27
1
Dogecoin
DOGE
$0.0792
1
Cardano
ADA
$0.1919
1
Avalanche
AVAX
$7.25
1
Polkadot
DOT
$0.9768
1
Chainlink
LINK
$10.73

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

🐋 Whale Tracker

🟢
0x58c0...e44a
12h ago
In
3,582 ETH
🟢
0xa64d...f2ea
6h ago
In
2,899 ETH
🔵
0x00f5...d861
12h ago
Stake
3,409,899 USDC

💡 Smart Money

0xedfb...5be2
Market Maker
+$3.7M
89%
0x1c1f...0eb7
Top DeFi Miner
-$2.0M
74%
0xf503...db50
Arbitrage Bot
+$0.4M
80%