Skip to content
Review

When Agents Act on Web3: An Attack-Surface Survey of MCP, Skills, and Tool Calling

Aug 2026 · 0 citations · 45 references
Computer Science

TL;DR

This survey argues that four properties of that layer (irreversibility, signing authority, continuous autonomy, and sequence-level composition) qualitatively change the threat model, turning the recoverable failures of generic agent security into a standing, irreversible loss.

Abstract

AI agents increasingly act rather than merely read: across the Model Context Protocol (MCP) ecosystem, the share of deployed tools that modify external state has risen from 27% to 65% of tool use. When agents exercise this authority on public blockchains through MCP, skills, and tool calling, the consequences of an attack are governed by the blockchain execution layer rather than by conventional software assumptions. This survey argues that four properties of that layer (irreversibility, signing authority, continuous autonomy, and sequence-level composition) qualitatively change the threat model, turning the recoverable failures of generic agent security into a standing, irreversible loss. We organize the fragmented MCP-security literature into an attack-surface taxonomy, then contribute a Web3 risk-mapping matrix that ties each attack class to its amplified impact, the responsible amplifiers, a representative mitigation, and the residual gap. We synthesize defenses, including emerging blockchain-based mechanisms, and find them improving but insufficient: measured protections stop fewer than 30% of attacks, and model-level safety refuses fewer than 3%. We close by positioning the work against adjacent surveys and deriving a research agenda from the matrix's open cells.

View source

Similar papers

Preprint Sep 2026

A Black Box for Agentic Processes: Blockchain-Anchored Evidence for AI Agent Communication, Human Oversight, and GRC Audits

Autonomous AI agents increasingly communicate with other agents, invoke tools, exchange intermediate results, and request human approvals. These workflows create a new auditability problem: organizations must reconstruct what happened, when it happened, which agent or human was involved, which control or policy applied, and whether records were modified afterwards. Motivated by the 2026 OpenAI/Hugging Face incident, this position and architecture paper proposes a product- and vendor-neutral black-box architecture for agentic processes. The architecture creates blockchain-anchored cryptographic commitments for selected agent communications, human-in-the-loop approvals, tool calls, and process artifacts without placing sensitive content on-chain. We define an evidence model that distinguishes temporal anchoring and artifact integrity from event ordering, capture authenticity, authorized anchoring, and causal traceability. The latter properties require additional architectural controls. We then discuss practical use for Governance, Risk, and Compliance (GRC), including compliance testing, risk-based evidence selection, monitoring evidence streams, incident reconstruction, and regulatory reporting readiness under the EU AI Act, NIS2, and the Cyber Resilience Act (CRA). This position and architecture paper does not present an empirical performance or security evaluation. The approach does not prevent agent misbehavior or prove semantic truth. Rather, it strengthens the evidentiary basis for later verification of critical process traces.

A. Brömme · 2 citations
Open access Jul 2026

THREAT MODELING OF AUTONOMOUS CODING AGENTS IN CORPORATE MOBILE DEVELOPMENT. PART 1: SYSTEM MODEL, ASSETS, TRUST BOUNDARIES, AND ATTACK SURFACES

The aim is to specify the system under analysis and to fix a reproducible threat-modeling methodology on which the remaining parts build, combining a data-flow diagram annotated with trust boundaries, attack-surface.

Valentyn Berkatiuk · 0 citations
Preprint Aug 2026

Beyond the Mandate: A Systematic Security Analysis of the Agent Payments Protocol (AP2)

A systematic security analysis of AP2 v0.2 based on its roles, transaction lifecycle, deployment architectures, and trust boundaries shows that valid mandate signatures alone do not ensure that an agent-mediated transaction reflects the user's intent when its pre-authorization context is manipulated.

Avital Aviv, Parth A. Gandh, Ron Bitton et al. · 0 citations
Open access Aug 2026

Beyond Verification: How Blockchain Technology Challenges the Future Role of External Auditors

It is argued that blockchain automates a narrow and historically labor-intensive slice of the audit, namely the verification of the existence, occurrence, and mathematical accuracy of recorded transactions, while leaving untouched the components of assurance that depend on professional judgment.

Gaduga Godwin · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.