BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Agentjacking Attack Tricks AI Coding Assistants

Agentjacking exploits AI coding assistants via fake Sentry errors to run malicious code on developer machines.

  • Researchers at Tenet Security have uncovered a new attack class called “Agentjacking” that tricks AI coding agents into executing malicious code.
  • The exploit uses a fake error report sent to the Sentry platform, which AI agents then interpret and act upon as legitimate troubleshooting steps.
  • The attack can expose sensitive developer data like environment variables and Git credentials without needing phishing or server compromise.
  • Sentry acknowledged the flaw but deemed it “technically not defensible,” opting for a limited content filter instead of a full fix.

Cybersecurity researchers from Tenet Security revealed in June 2026 a novel attack vector that manipulates trusted AI coding assistants, a technique they’ve dubbed Agentjacking. This method allows an attacker to run arbitrary code directly on a developer’s machine by exploiting the integration between AI agents and the Sentry error-monitoring service.

- Advertisement -

The attack, as detailed by the researchers, begins when an attacker obtains a target’s publicly available Sentry Data Source Name (DSN). Consequently, they can send a maliciously crafted error event to Sentry’s ingest endpoint. This injected payload contains markdown formatted to mimic legitimate Sentry system output.

When a developer prompts their AI agent to fix unresolved issues, the agent retrieves the malicious event via the Model Context Protocol. However, the agent cannot distinguish the fake error from a real one. The AI coding assistant then executes the attacker’s code with the developer’s full system privileges.

This chain results in what the researchers call a “critical architectural flaw.” Meanwhile, the attacker never needs to breach the victim’s infrastructure directly. “The malicious instruction arrives disguised as a legitimate ‘Resolution’ inside an ordinary error,” the researchers explained.

Tenet Security tested the attack in a controlled environment, achieving an 85% success rate. They found at least 2,388 organizations with injectable DSNs. Sentry has activated a global filter for a specific payload string but maintains a broader fix is not feasible.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bybit adds Unitree, Moonshot AI to pre-IPO perpetuals

Bybit has launched pre-IPO perpetual contracts for Chinese robotics firm Unitree and AI startup...

Apple and Alibaba team up to launch AI in China

Apple trained its own large language model for the Chinese market with support from...

Trump to Host Crypto CEOs as Bitcoin Stays Flat at $60K

President Donald Trump is expected to attend a White House meeting with top crypto...

Analyst: Bitcoin $1M by 2030 ‘mathematically impossible’

Markus Thielen of 10x Research calls a $1 million Bitcoin by 2030 "mathematically impossible"...

Galaxy lowers CLARITY Act passage odds to 10%

Galaxy Digital now estimates only a 10% chance the CLARITY Act will pass in...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading