A recent study by Astrix Research has revealed significant security risks in the way Model Context Protocol (MCP) servers, which connect artificial intelligence tools to external applications and data sources, handle authentication. The research examined over 5,200 open-source MCP server implementations and found that 88% of these servers require credentials for access. However, more than half of the servers rely on long-lived, static secrets such as API keys and personal access tokens, rather than adopting more secure, short-lived or delegated access tokens. This widespread use of static credentials increases the risk of credential theft or misuse, especially if the servers or their environments are compromised. Only a small fraction of the surveyed servers utilize OAuth, the industry standard for secure authorization, indicating a lag in the adoption of best practices for identity and access management. MCP servers function as intermediaries, enabling AI models to retrieve information and perform actions on external systems, which makes the security of their authentication mechanisms critical. The study traced the prevalence of static credential usage back to the early days of the MCP protocol, when Anthropic introduced the protocol in 2023. Initial sample servers provided by Anthropic used personal access tokens and basic passwords for demonstration purposes. Although subsequent examples improved on these defaults, the insecure patterns established early on have persisted in the broader community. The research highlights that credentials are often stored insecurely, such as directly in configuration files or passed as environment variables, further compounding the risk of unauthorized access. The findings underscore the urgent need for scalable identity security frameworks tailored to AI agent environments. The report calls for developers to move away from static secrets and adopt modern authentication protocols like OAuth to mitigate the risk of credential compromise. The study also points out that the rapid growth of AI agent systems has outpaced the implementation of robust security controls, leaving many deployments vulnerable. Security experts warn that attackers could exploit these weaknesses to gain unauthorized access to sensitive data or manipulate AI-driven processes. The research recommends that organizations audit their MCP server deployments for insecure credential practices and prioritize the adoption of short-lived, delegated credentials. The issue is particularly pressing as AI agent systems become more deeply integrated into critical business operations. The study serves as a wake-up call for the AI development community to address authentication weaknesses before they are exploited at scale. Organizations are advised to review their current practices and update their security policies to reflect the evolving threat landscape. The report concludes that improving authentication mechanisms in MCP servers is essential to safeguarding the integrity and confidentiality of AI-powered systems.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Reporting and research published in mid-October 2025 described a security weakness in Model Context Protocol (MCP) servers stemming from the use of static credentials, warning that the practice increases the risk of unauthorized access and broader compromise. Multiple references cover the same underlying finding, with no separate real-world incidents or remediation events described.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
reversinglabs.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.