Skip to content
Computing Life · Share · Yage

Agentjacking: Fake Sentry errors hijack Claude Code with 85% success rate

Agentjacking:一段假错误报告,85% 概率劫持你的 Claude Code

Tenet Security disclosed Agentjacking: attackers submit fake Sentry error events using your publicly exposed frontend DSN, embedding malicious commands disguised as fix suggestions. When your AI coding agent pulls Sentry issues via MCP and auto-fixes bugs, it follows the injected instructions 85% of the time. Tests covered 100+ instances across Claude Code, Cursor, and Codex. Passive scanning found 2,388 organizations with exposed DSNs, including a ~$250B Fortune 500 company. Every step in the chain is authorized—EDR, WAF, and firewalls see nothing. The root cause isn't Sentry; AI agents can't distinguish data they read from instructions to act. The same pattern has been confirmed in WhatsApp MCP, web scraper MCP, Cursor rules files, Claude Code file reads, and RAG systems. Smarter prompts won't fix this because trusted instructions and untrusted data merge into the same token stream with no architectural boundary. Sentry declined a root-cause fix, adding only a bypassable content filter. Current defenses—sandboxing, least privilege, human approval—only limit blast radius, not the injection itself.

Why it matters: Tenet Security's Agentjacking disclosure is the first systematically validated supply-chain attack on the MCP ecosystem—85% success rate, 2,388 exposed orgs, Fortune 500 victims, all with hard data. It exploits design trust rather than a vulnerability, leaving EDR/WAF complete...

Read the original ↗Export Markdown