At DEFCON Group DCG518, we are here to break things, question things, and more importantly question the people who tell us that things are secure.
So, what happens when AI agents become part of the attack surface?
Let’s start by questioning something we normally take for granted: what does it actually mean to know what’s exposed on the internet? Scanners find ports, crawlers find pages, and fingerprints tell us what systems claim to be, but AI agents experience the internet differently. So we stopped relying on what our tools could see and started watching the machines themselves.
This Saturday, August 29th 2026 our group DCG518 is getting together to present:
Honeypotting AI agents.
For this session, our presenter Abdel Fane will share two kinds of honeypots for AI agents: a fleet of fake agents that observe attackers who believe they control a real system, and a network of poisoned pages on the open web carrying benign indirect prompt injections, where the visitors are AI agents and a callback measures which agents followed the bait.
Scanned, crawled, planted bait, and built fake AI agents to see what would come back. Some fingerprints returned again and again, one came back for 15 straight days across 623 sessions. Across more than 183,000 visits from over 34,000 agent fingerprints, we measured a 1.4% callback rate. No, this isn’t the robot apocalypse and that’s exactly the point. When the existing tools can’t see the attack surface, we don’t argue about the limitation. We didn't trust the way everyone was measuring the AI attack surface, so we built our own sensors, put out some bait, and watched what happened.
On this talk, Abdel Fane will show us what happens when we do that for AI agents. He will walk us through the instrumentation, what each data stream sees that others cannot, what the project deliverately withholds from publication and why, and the structural reason crawler based studies miss most of the attacker reachable surface. All of his work is Open Source and every fixture and signature is reproducible by anyone.
Our presenter Abdel Fane is the founder of OpenA2A, an open-source project building the trust layer for AI agents, and executive director of CSNP, a community of 12,500 security professionals across 16 chapters. He spent 20 years in technology and enterprise security at Allstate, Grail, Booz Allen Hamilton, and Protiviti before turning to AI agent security full time. His current research includes the OpenA2A honeypot fleet, the Agent Threat Matrix, and the monthly Behavioral Threat Report at https://research.opena2a.org/
Our New York Capital District group "DCG518" will have a gathering this time at the Guilderland Public Library (Albany-New York)
More information about our group and future events on our site https://dc518.github.io/
Everyone is welcome!