Search papers, labs, and topics across Lattice.
This paper surveys the evolving landscape of AI agents operating within the Model Context Protocol (MCP) ecosystem, highlighting a significant increase in the use of tools that modify external states on public blockchains. It identifies four critical properties of the blockchain execution layer鈥攊rreversibility, signing authority, continuous autonomy, and sequence-level composition鈥攖hat fundamentally alter the threat model for agent security, leading to irreversible losses rather than recoverable failures. The authors provide a comprehensive attack-surface taxonomy and a risk-mapping matrix, revealing that current defenses are inadequate, with less than 30% of attacks mitigated and model-level safety rejecting fewer than 3% of threats.
The shift from recoverable failures to irreversible losses in AI agent security on blockchains could redefine our understanding of attack vectors in Web3 environments.
AI agents increasingly act rather than merely read: across the Model Context Protocol (MCP) ecosystem, the share of deployed tools that modify external state has risen from 27% to 65% of tool use. When agents exercise this authority on public blockchains through MCP, skills, and tool calling, the consequences of an attack are governed by the blockchain execution layer rather than by conventional software assumptions. This survey argues that four properties of that layer (irreversibility, signing authority, continuous autonomy, and sequence-level composition) qualitatively change the threat model, turning the recoverable failures of generic agent security into a standing, irreversible loss. We organize the fragmented MCP-security literature into an attack-surface taxonomy, then contribute a Web3 risk-mapping matrix that ties each attack class to its amplified impact, the responsible amplifiers, a representative mitigation, and the residual gap. We synthesize defenses, including emerging blockchain-based mechanisms, and find them improving but insufficient: measured protections stop fewer than 30% of attacks, and model-level safety refuses fewer than 3%. We close by positioning the work against adjacent surveys and deriving a research agenda from the matrix's open cells.