arXiv:2507.19880cs.CRcs.AI2025-07被引 8

黑客用简单工具伪装天气服务,竟能窃取银行账户余额。

Trivial Trojans: How Minimal MCP Servers Enable Cross-Tool Exfiltration of Sensitive Data

  • 用伪装成天气服务的恶意MCP服务器,诱骗用户调用合法银行工具。
  • 仅需本科编程水平即可完成攻击,无需服务器或资金投入。
  • 揭示MCP生态中跨服务器信任链的致命漏洞,适合安全研究者关注。

模型上下文协议(MCP)实现了AI代理与外部服务间的无缝通信,但其连接性也带来了未被充分探索的新攻击路径。本文展示,具备基础编程能力的攻击者仅需免费网络工具,即可利用MCP的信任机制窃取敏感财务数据。通过一个概念验证攻击,我们演示了伪装成良性功能的恶意天气MCP服务器如何发现并滥用合法银行工具,获取用户账户余额。整个攻击链无需高级技术知识、服务器基础设施或金钱投入。研究揭示:尽管单个MCP服务器看似可信,但其组合会形成意想不到的跨服务器攻击面。与传统假设复杂对手不同,本研究表明MCP攻击的门槛极低。具备本科级Python技能的攻击者可构造有说服力的社会工程攻击,利用MCP建立的隐式信任关系进行渗透。本文为新兴的MCP安全领域做出贡献,证明当前实现允许轻量级跨服务器攻击,并提出即时缓解措施与协议改进建议以保障该生态系统安全。

原文摘要 · Abstract (English)

The Model Context Protocol (MCP) represents a significant advancement in AI-tool integration, enabling seamless communication between AI agents and external services. However, this connectivity introduces novel attack vectors that remain largely unexplored. This paper demonstrates how unsophisticated threat actors, requiring only basic programming skills and free web tools, can exploit MCP's trust model to exfiltrate sensitive financial data. We present a proof-of-concept attack where a malicious weather MCP server, disguised as benign functionality, discovers and exploits legitimate banking tools to steal user account balances. The attack chain requires no advanced technical knowledge, server infrastructure, or monetary investment. The findings reveal a critical security gap in the emerging MCP ecosystem: while individual servers may appear trustworthy, their combination creates unexpected cross-server attack surfaces. Unlike traditional cybersecurity threats that assume sophisticated adversaries, our research shows that the barrier to entry for MCP-based attacks is alarmingly low. A threat actor with undergraduate-level Python knowledge can craft convincing social engineering attacks that exploit the implicit trust relationships MCP establishes between AI agents and tool providers. This work contributes to the nascent field of MCP security by demonstrating that current MCP implementations allow trivial cross-server attacks and proposing both immediate mitigations and protocol improvements to secure this emerging ecosystem.

MCP安全数据泄露社会工程

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。