MMAchain
Industry

The Ghost in the MCP: How Public Sentry DSNs Turn AI Agents Into Credential Leakers

SatoshiStacker

2,388 public Sentry DSNs. 71 in the top 1 million websites. 27% of Fortune 1000 companies. These numbers are not a vulnerability count. They are the attack surface for a new class of AI agent credential theft.

The Ghost in the MCP: How Public Sentry DSNs Turn AI Agents Into Credential Leakers

Silence speaks louder than the algorithmic hum. At DEF CON 34, Tenet Security presented a proof-of-concept that transforms a common error monitoring tool into an instruction injection vector. The target is not a blockchain protocol, but the developers who build them. The implication for crypto hedge funds, DeFi protocols, and on-chain infrastructure is immediate: if your team uses AI coding agents with MCP (Model Context Protocol) integrations, your private keys are one POST request away from compromise.

Context: The Model Context Protocol (MCP) is an open standard championed by Anthropic that allows AI agents like Claude Code and Cursor to read from external data sources—databases, APIs, error logs. Sentry, a popular error monitoring platform, exposes a public ingestion endpoint (a DSN) that accepts any POST request with the correct project ID. No authentication on the payload. No signature verification. The design is intentional: Sentry wants to capture crashes from anywhere. The risk is that MCP-connected agents treat Sentry issues as trusted context. The agent reads the error description, and if that description contains a malicious markdown block, the agent may execute it as a repair command.

Tracing the ghost in the validator’s code. The attack chain is elegant, mechanical, and reproducible. Step one: scan for exposed Sentry DSNs—there are 2,388 organizations with public DSNs according to Tenet’s analysis. Step two: POST a crafted error event to the DSN endpoint. The payload includes a markdown block that mimics a legitimate fix suggestion: "npm install @sentry/security-patch". Step three: wait for a developer to ask their AI agent to read the Sentry issue. The agent fetches the issue, sees the markdown, and interprets it as a repair instruction. Step four: the agent executes npm install with the malicious package name. The package contains a post-install script that exfiltrates environment variables, including AWS keys, GitHub tokens, npm tokens, and—crucially—any private keys stored in the developer’s environment. The agent believes it is helping. The developer believes the agent is secure. The ledger remembers what eyes forget.

Beauty hides in the candle’s wick. The elegance of this attack is its asymmetry. The attacker invests one HTTP POST. The victim invests a full developer workflow. The agent’s trust in structured data is the candle’s wick—thin, fragile, and burning from both ends. Tenet reported an 85% success rate in controlled tests across 100+ organizations. The number is striking, but it comes with a condition: the attack only fires when a developer actively asks the agent to debug a Sentry issue. The correlation is not causation. The 85% figure reflects the probability of success given that trigger condition, not the probability of random exploitation. This is the contrarian angle: the attack is not a silent, automated exploit. It requires a human to initiate the chain. In a sideways market, where developers are less frantic, the likelihood of such a workflow is lower. Yet the vector remains valid.

The industry response reveals the deeper architecture problem. Sentry deployed a content filter—a string blacklist against specific payload patterns. This is an IoC-level patch. It can be bypassed with simple obfuscation. Tenet released agent-jackstop, a drop-in configuration that applies network whitelisting, command execution approval, and subprocess credential protection. These are blast radius reduction measures, not root cause fixes. The root cause is that AI agents cannot semantically distinguish between data and instructions when the data is formatted as a structured fix. The model sees a markdown code block and assumes it is a command. The MCP protocol does not require a trustworthiness tag on tool outputs. The architecture assumes all data is equally trustworthy. That assumption is now a liability.

For crypto teams, the takeaway is binary. If your developers use AI coding agents with MCP access to Sentry or any external error monitoring service, you are exposed. The exposure is not theoretical—it has been demonstrated with a proof-of-concept that is reproducible. The immediate signal: isolate your agent’s network. Use agent-jackstop or equivalent to enforce that the agent cannot execute shell commands without explicit approval. Treat all external data sources as untrusted, even if they are internal systems like Sentry. The broader signal: the MCP ecosystem is entering a security phase. The protocol must evolve to include a trust layer—a mechanism for data sources to declare their intent and for agents to verify that intent. Until then, the ghost in the MCP will remain.

Color coded, not just counted. The 2,388 public DSNs are not just numbers. They are the color of a market that has not yet priced in the security cost of AI integration. The beauty of the attack is its mathematical simplicity. The wick is thin. The candle is burning. The question is whether the industry will rewrite the protocol before the fire spreads.

Market Prices

BTC Bitcoin
$64,383.2 -0.94%
ETH Ethereum
$1,892.17 -1.19%
SOL Solana
$75.93 -1.18%
BNB BNB Chain
$613.1 +1.49%
XRP XRP Ledger
$1.01 -2.39%
DOGE Dogecoin
$0.0707 +1.03%
ADA Cardano
$0.1880 -4.37%
AVAX Avalanche
$6.48 -0.81%
DOT Polkadot
$0.7986 -1.47%
LINK Chainlink
$8.65 +4.04%

Fear & Greed

29

Fear

Market Sentiment

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$64,383.2
1
Ethereum ETH
$1,892.17
1
Solana SOL
$75.93
1
BNB Chain BNB
$613.1
1
XRP Ledger XRP
$1.01
1
Dogecoin DOGE
$0.0707
1
Cardano ADA
$0.1880
1
Avalanche AVAX
$6.48
1
Polkadot DOT
$0.7986
1
Chainlink LINK
$8.65

🐋 Whale Tracker

🟢
0xf4cb...bbbb
12m ago
In
39,773 BNB
🔴
0xca4f...4635
2m ago
Out
925 ETH
🔵
0xe06a...bbc6
5m ago
Stake
2,262,069 USDT

💡 Smart Money

0x3709...64af
Arbitrage Bot
+$3.6M
81%
0x4c93...feed
Arbitrage Bot
-$0.7M
88%
0x3e0f...fea5
Experienced On-chain Trader
-$4.7M
82%

Tools

All →