Honeypotting AI Agents
OpenA2A runs two kinds of honeypot for AI agents: a fleet of fake agents that observe attackers who believe they control a real system, and a network of poisoned pages on the open web carrying benign indirect prompt injections, where the visitors are AI agents and a callback measures which agents followed the bait. This talk presents what both surfaces reveal, including the finding that 45 percent of unique attackers return across sessions, with one fingerprint returning for 15 days straight across 623 sessions, alongside an aggregate callback rate of 1.4 percent across more than 183,000 visits from over 34,000 unique agent fingerprints. Abdel Fane walks through the instrumentation, what each data stream sees that the others cannot, what the project deliberately withholds from publication and why, and the structural reason crawler-based studies miss most of the attacker reachable surface. All of the work is Apache 2.0, and every fixture and signature is reproducible by anyone running equivalent instrumentation.
Sunday 1400 Gramercy Park Suite