SourcesUnit42: MCP Sampling Attack Vectors (Resource Theft, Hijacking)Unit42 Palo Alto·high signalXBlueskyLinkedInCopy linkThree critical MCP sampling attacks: resource theft, conversation hijacking, covert tool invocation. Zero built-in security controls.SourceSource pageUnit42 Palo Alto↳ Follow the threadPolicy dependency / Stack layer'Do this as quickly as possible' repeatedly got a Claude session flagged by a corporate security directorr/ClaudeAIPolicy dependency / Stack layerConverting GUI Trajectories Into Replayable MCP-Style Calls Instead of Unstructured MemoriesarXiv 2609.16635Policy dependency / Stack layerOrdewell uses a read-only coding agent as planner, then spawns per-task agent sessions gated by a marker-based verdict engineGitHubStack layer / Threat patternEmergence World ran 10 agents per world for 16 days and found no frontier model contained an injected attack — one acted on poisoned memory 46 hours laterarXivStack layer / Threat patternTypeSafe AI ships Jev, a model that returns typed probabilistic values instead of text, at $0.042 per million input tokens and free outputTypeSafe AIPolicy dependency / Stack layerPython's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or CriticalarXiv 2609.14791Stack layer / Threat patternRemoving the Tenant ID From an MCP Tool Schema Blocks Cross-Tenant Reads That a Validated Parameter Let Through 26 Times Out of 26arXiv 2609.14780Stack layer / Threat patternTwo Tool-Level Defenses Drive Prompt Injection and Memory Poisoning to 0% Attack Success in Many SettingsarXiv 2609.16098