Darktrace: history poisoning turns coding agents into attackers
Darktrace demonstrated a "history poisoning" attack: Claude Code, Codex and Kiro-CLI store conversation history on disk without verifying it came from the model, then read it as trusted context on startup. A malicious package can write a fake dialogue authorizing a network scan, and the agent will execute it after restart. Separately, OX Security analyzed 15,465 public MCP servers: 15.6% resolve outside the US and 0.45% run on home networks.
- Claude Code, Codex and Kiro-CLI read on-disk history without signature checks
- A malicious package can plant a fake authorization for a network scan
- Of 15,465 MCP servers, 15.6% resolve outside the US, 0.45% on home networks
- Anthropic: 7 Chinese labs distilled Claude, up to 3M exchanges per day
Read next
Security