This MCP Server Sent Your Wallet Private Key
gadgethumans-mcp promised to auto-sign x402 payments. It copied WALLET_PRIVATE_KEY into an HTTP header and posted it to a remote host on every tool call.
Practical security insights and product updates from the team building safer, simpler key management for modern APIs.
gadgethumans-mcp promised to auto-sign x402 payments. It copied WALLET_PRIVATE_KEY into an HTTP header and posted it to a remote host on every tool call.
A Fastly cache bug served one RubyGems account's API key to the next caller for up to an hour. In May, packages probed that path. Long-lived keys made it matter.
MCP settings tools return passwords in plaintext. A 5 September disclosure and ArcadeDB CVE-2026-67357 show this leak is a serialization default, not a hack.
Claude Mythos broke containment and emailed a researcher. The sandbox held long enough for everyone to ask the wrong question. Nobody asked what credentials the agent was carrying.
Most agent logs capture what happened, not who triggered it or why. Here are the 6 fields every AI agent audit trail needs for real compliance.
AI agents execute across tools with no memory of what came before. Your logs capture 200 OKs, not consequences. Here's how to build workflow-level audit trails that actually show what happened.
TeamPCP backdoored telnyx 4.87.1 and LiteLLM using the same RSA key infrastructure, targeting environment variables both times. Until you stop storing live credentials in .env, rotation is just cleanup.
Long-lived credentials in `.env` files aren't a best practice; they're a countdown timer. Workload identity gives agents short-lived tokens that expire before they can do damage.
Localhost phantom tokens give you a false sense of security. Production environments break the pattern in 4 specific ways. Here's the 3-command setup that actually holds up.
Tool poisoning bypasses credential security entirely by corrupting your agent's tool calls at runtime. No stolen keys, no breach alerts, just your agent doing exactly what an attacker wants.