Honeypotting AI Agents

Abdel Fane

OpenA2A runs two kinds of honeypot for AI agents: a fleet of fake agents that observe attackers who believe they control a real system, and a network of poisoned pages on the open web carrying benign indirect prompt injections, where the visitors are AI agents and a callback measures which agents followed the bait. This talk presents what both surfaces reveal, including the finding that 45 percent of unique attackers return across sessions, with one fingerprint returning for 15 days straight across 623 sessions, alongside an aggregate callback rate of 1.4 percent across more than 183,000 visits from over 34,000 unique agent fingerprints. Abdel Fane walks through the instrumentation, what each data stream sees that the others cannot, what the project deliberately withholds from publication and why, and the structural reason crawler-based studies miss most of the attacker reachable surface. All of the work is Apache 2.0, and every fixture and signature is reproducible by anyone running equivalent instrumentation.

Sunday 1400 Gramercy Park Suite


Abdel Fane is the founder of OpenA2A, an open-source project building the trust layer for AI agents, and executive director of CSNP, a community of 12,500 security professionals across 16 chapters. He spent 20 years in technology and enterprise security at Allstate, Grail, Booz Allen Hamilton, and Protiviti before turning to AI agent security full time. His current research includes the OpenA2A honeypot fleet, the Agent Threat Matrix, and the monthly Behavioral Threat Report at research.opena2a.org.