BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Agentjacking Attack Tricks AI Coding Assistants

Agentjacking exploits AI coding assistants via fake Sentry errors to run malicious code on developer machines.

  • Researchers at Tenet Security have uncovered a new attack class called “Agentjacking” that tricks AI coding agents into executing malicious code.
  • The exploit uses a fake error report sent to the Sentry platform, which AI agents then interpret and act upon as legitimate troubleshooting steps.
  • The attack can expose sensitive developer data like environment variables and Git credentials without needing phishing or server compromise.
  • Sentry acknowledged the flaw but deemed it “technically not defensible,” opting for a limited content filter instead of a full fix.

Cybersecurity researchers from Tenet Security revealed in June 2026 a novel attack vector that manipulates trusted AI coding assistants, a technique they’ve dubbed Agentjacking. This method allows an attacker to run arbitrary code directly on a developer’s machine by exploiting the integration between AI agents and the Sentry error-monitoring service.

- Advertisement -

The attack, as detailed by the researchers, begins when an attacker obtains a target’s publicly available Sentry Data Source Name (DSN). Consequently, they can send a maliciously crafted error event to Sentry’s ingest endpoint. This injected payload contains markdown formatted to mimic legitimate Sentry system output.

When a developer prompts their AI agent to fix unresolved issues, the agent retrieves the malicious event via the Model Context Protocol. However, the agent cannot distinguish the fake error from a real one. The AI coding assistant then executes the attacker’s code with the developer’s full system privileges.

This chain results in what the researchers call a “critical architectural flaw.” Meanwhile, the attacker never needs to breach the victim’s infrastructure directly. “The malicious instruction arrives disguised as a legitimate ‘Resolution’ inside an ordinary error,” the researchers explained.

Tenet Security tested the attack in a controlled environment, achieving an 85% success rate. They found at least 2,388 organizations with injectable DSNs. Sentry has activated a global filter for a specific payload string but maintains a broader fix is not feasible.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Fomo overtakes Pump.fun in daily revenue on Solana

Social trading platform Fomo generated $1.76 million in daily revenue on Friday, surpassing memecoin...

Inflation Data Looms Over Stocks & Crypto This Week

The US market will be closed on Monday for Labor Day, but the cryptocurrency...

Micron stock all-time high talk grows pre Sept. 30 earnings

Micron shares trade near $980, over 20% below the June 2026 closing record of...

Pencil Finance completes $1M on-chain student loan cycle

Pencil Finance completed a $1 million student-loan cycle fully on-chain, from investor capital to...

Bitcoin Trades More Like Gold, Bolstering Digital Gold Case

Bitcoin's 90-day correlation with Gold climbed to its highest level since 2020, while its...

Must Read

How to Check The Rarity of An NFT

Whenever you invest in an NFT collection, you might have noticed that some NFTs are more expensive than others. NFT collections are often made...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading