
MCP servers have become AI's newest attack surface
Model Context Protocol, the standard Anthropic introduced in November 2024 to let AI agents connect to outside tools and data, has grown into critical infrastructure faster than anyone has managed to secure it. By December 2025, Anthropic counted more than 10,000 active public MCP servers running across ChatGPT, Gemini, Microsoft Copilot, Cursor, and Visual Studio Code, according to AI News.
- A review of those servers by Lakera, since acquired by Check Point, found that 40% carried exploitable weaknesses
- OWASP lists tool poisoning, embedding malicious instructions inside a tool's own description, as a leading MCP threat
- "Rug pull" attacks let a server change its tool definitions after a user has already approved it, exploiting established trust
- Other documented risks include tool shadowing, cross-origin escalation, and covert data exfiltration through legitimate-looking tool calls
- "Always allow" permission settings on read-only tools can turn a single compromised server into a zero-click attack path
The core problem is architectural, not incidental. An MCP server's tool description is unsanitized text that the connected agent reads and can act on, and there is no built-in way for the agent to tell a legitimate instruction apart from one buried by an attacker inside what looks like ordinary help text. The agent doesn't need to be tricked twice: once a server is approved, everything it later claims about its own tools is taken largely on faith.
Intokened has tracked a parallel record of AI agents going wrong in production, including a running tally of 17 documented cases where agents caused real breaches at real companies, and a separate report on state-linked hacking groups in China that doubled attacks after adopting AI tooling. MCP's growth curve adds a new, largely unaudited layer underneath both trends: the tools an agent calls, not just the model making the calls.
Security vendors are only now catching up. Check Point folded Lakera's research into a dedicated AI Network Firewall in July 2026, Cisco extended its AI Defense product to cover MCP traffic, and infrastructure startup TrueFoundry built an AI Gateway aimed at the same gap. None of it changes the underlying math: the protocol shipped, adoption exploded across every major AI platform within about twelve months, and the tooling built to police it arrived roughly a year after that.
For now, the number worth watching isn't a dollar figure or a single named breach. It's the 40% failure rate on a review sample drawn from a system with 10,000-plus live deployments, most of them installed by developers who never audited what the server on the other end of the connection was actually doing.
This article is for informational purposes only and does not constitute investment advice.

Comments (0)
No comments yet — be the first!
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
268AI





