Researchers demonstrate that large language models using the Model Context Protocol for tool-calling are vulnerable to cross-channel fragmentation attacks, where malicious payloads distributed across multiple input channels can bypass single-channel defenses and achieve credential exfiltration at rates up to 100% in frontier models. Existing security tools and prompt-based defenses failed to detect these attacks.
Pact0, an AI agent marketplace, tested 11 AI agents autonomously completing paid microtasks with minimal guidance. Only 3 successfully registered, verified identity, claimed a job, and received payment ($0.05 each), while frontier models like GPT-4o failed due to poor UX design, missing context windows, and unclear instructions.