This MCP Server Sent Your Wallet Private Key
gadgethumans-mcp promised to auto-sign x402 payments. It copied WALLET_PRIVATE_KEY into an HTTP header and posted it to a remote host on every tool call.
Practical security insights and product updates from the team building safer, simpler key management for modern APIs.
gadgethumans-mcp promised to auto-sign x402 payments. It copied WALLET_PRIVATE_KEY into an HTTP header and posted it to a remote host on every tool call.
MCP settings tools return passwords in plaintext. A 5 September disclosure and ArcadeDB CVE-2026-67357 show this leak is a serialization default, not a hack.
Localhost phantom tokens give you a false sense of security. Production environments break the pattern in 4 specific ways. Here's the 3-command setup that actually holds up.
Tool poisoning bypasses credential security entirely by corrupting your agent's tool calls at runtime. No stolen keys, no breach alerts, just your agent doing exactly what an attacker wants.
135,000 exposed OpenClaw instances, 824+ malicious skills, and a CVSS 8.8 RCE in 2026. Here's what went wrong and how to stop your API keys from being the next casualty.