When Agents Act on Web3: An Attack-Surface Survey of MCP, Skills, and Tool Calling

📅 2026-08-17
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文探讨了AI代理在Web3环境下通过MCP、技能和工具调用时的安全威胁,提出了一个攻击面分类法,并分析了现有防御措施的不足。
📝 Abstract
AI agents increasingly act rather than merely read: across the Model Context Protocol (MCP) ecosystem, the share of deployed tools that modify external state has risen from 27% to 65% of tool use. When agents exercise this authority on public blockchains through MCP, skills, and tool calling, the consequences of an attack are governed by the blockchain execution layer rather than by conventional software assumptions. This survey argues that four properties of that layer (irreversibility, signing authority, continuous autonomy, and sequence-level composition) qualitatively change the threat model, turning the recoverable failures of generic agent security into a standing, irreversible loss. We organize the fragmented MCP-security literature into an attack-surface taxonomy, then contribute a Web3 risk-mapping matrix that ties each attack class to its amplified impact, the responsible amplifiers, a representative mitigation, and the residual gap. We synthesize defenses, including emerging blockchain-based mechanisms, and find them improving but insufficient: measured protections stop fewer than 30% of attacks, and model-level safety refuses fewer than 3%. We close by positioning the work against adjacent surveys and deriving a research agenda from the matrix's open cells.
Problem

Research questions and friction points this paper is trying to address.

AI agents
Web3
blockchain
security threats
attack surface
Innovation

Methods, ideas, or system contributions that make the work stand out.

irreversibility
signing authority
continuous autonomy
sequence-level composition
🔎 Similar Papers
No similar papers found.
R
Rabimba Karanjai
University of Houston, USA; PayPal AI Labs, USA
Y
Yang Lu
University of Houston, USA
N
Nour Diallo
University of Houston, USA
W
Wujie Xiong
Kent State University, USA
Lei Xu
Lei Xu
Computer Science Department, Kent State University
Protect computation & communication & storage for good.
W
Weidong (Larry) Shi
University of Houston, USA