Unsigned AI agent history files open door to silent code execution attacks
Cybersecurity firm Darktrace has demonstrated that popular coding agents — including Claude Code, Codex, and Kiro-CLI — store conversation history on disk without verifying its authenticity, allowing malicious packages to inject fake instructions that the agent executes on restart. Separately, a study by OX Security of over 15,000 public MCP servers found that nearly 16% resolve outside the US, with dozens traced to China and Russia, and some pointing to abandoned domains still active in live configurations. Anthropic also disclosed that seven Chinese labs ran large-scale unauthorized distillation campaigns against Claude, with one operation generating nearly 3 million daily exchanges from thousands of fraudulent accounts. Meanwhile, crypto exchange Bitget confirmed a $351.6 million hack — the largest of 2026 — in which attackers forged transactions by compromising an internal approval system rather than stealing private keys. Security researchers warn that the common thread across all three incidents is a failure to treat agent-consumed context as untrusted input, and urge the industry to implement verifiable signatures on agent history rather than issuing narrow patches.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in