Indirect prompt injection attacks are becoming significantly harder against the newest AI models, with Anthropic's Opus 5.5 succeeding only 1% of the time versus 1 in 4 or worse for many others. However, real-world attacks remain a threat, criminals are exploiting the vulnerability to steal API keys, and older models remain vulnerable. Security researchers recommend benchmarking agentic applications across models and restricting MCP tool access.