A change to the Model Context Protocol (MCP) stateless core did not remove session risk so much as relocate it to application-layer identifiers that large language models must preserve across turns. The reported design leaves servers relying on models to correctly carry and replay values such as basket IDs, browser IDs, and tenant-linked handles, creating opportunities for silent misrouting, cross-tenant actions, workflow hijacking, and unauthorized data access when a model drops context or uses the wrong identifier.
The warning is reinforced by research on multi-turn degradation in LLMs, including the paper LLMs Get Lost In Multi-Turn Conversation, which found models struggle as conversations lengthen and information must be retained accurately across turns. The report also cites a Red Hat incident in which an agent chose the wrong account despite the correct identifier being present in prompt context, underscoring that valid-looking but incorrect requests can still succeed. Recommended defenses include per-request authorization of handles, short-lived high-entropy identifiers, idempotency keys, and testing agent workflows at deeper conversation turn counts.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
On July 28, 2026, the Model Context Protocol changed to a stateless core that removed protocol-managed session state such as session identifiers and negotiated session correlation. Servers needing cross-call state were instead directed to mint explicit handles like basket IDs or browser IDs and rely on the model to pass them back in later tool calls.
The paper "LLMs Get Lost in Multi-Turn Conversation" reported results from more than 200,000 simulated conversations across fifteen leading open- and closed-weight models. It found substantial degradation in multi-turn settings, including a 39% average performance drop, about 16% lower aptitude, and 112% higher unreliability, with function calling among the tested tasks.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.