Back to all news
Security

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

The Hacker News·August 11, 2026·1 min read
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server can trick AI coding assistants into exfiltrating SSH keys, environment secrets, source code, and customer data. The attack splits requests into fragments that each appear routine and places them in channels the assistant already uses, bypassing blunt theft refusal checks. The technique works without sending any obviously harmful instructions to the assistant.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store