September 28th Research Briefing
Contents
- AgentXploit: repo-to-runtime red-teaming recovers 72 agent vulns
- No Place to Hide: protected order flow still gets sandwiched
- OllamaDrama: honeypot measures real attacks on exposed Ollama

AgentXploit: repo-to-runtime red-teaming recovers 72 agent vulns
AgentXploit is a two-role white-box auditor for AI-agent codebases. An Analyzer Agent searches the repository and records code-supported attack paths from attacker-controlled inputs to sensitive operations. An Exploiter Agent then validates those paths at runtime through the task-defined attacker interface, while an external deterministic verifier decides success. AgentXploit-Bench ships 72 reproducible vulnerabilities across 12 open-source agent systems, drawn from public CVEs and security issues with pinned runtimes.
This matters because most agent red-teaming assumes the injection point is already known. Real pre-deployment audit still has to recover a feasible path from source before any payload can be judged exploitable.
Across three runs, end-to-end success averages 59.3% versus 38.4% for Codex (46.3% under a token-budget match). On AgentDojo, where injection points are supplied, the Exploiter reaches 79.2% versus 52.7% for AgentVigil. Most end-to-end failures localize to discovery, and audits also surface eight additional out-of-target findings across four projects (SSRF, command injection, and related classes).
Authors: Weida Liang, Shi Qiu, Zhun Wang, Simon Sure, Xiaoyuan Liu, Tianneng Shi, Zhaorun Chen, Wenbo Guo, and Dawn Song (paper, pdf, AgentXploit). Wenbo Guo: GitHub, X, LinkedIn.
No Place to Hide: protected order flow still gets sandwiched
No Place to Hide is a three-year longitudinal measurement of sandwich attacks against protected order flow across Ethereum, Solana, Tron, Base, Arbitrum, and Monad. The study covers private RPCs, local mempools, first-come-first-served ordering, and sequencers. Novel heuristics catch wide and cross-block sandwiches and filter persistent bots so counts separate attacks from ordinary trading.
This matters because users treat private submission and alternate ordering as sandwich protection. The measurement shows those guarantees can fail at every layer from wallet to consensus.
Against supposedly protected transactions the authors report 28.0 million sandwiches on Solana, 38,567 on Tron, 30,607 on Ethereum, and 1,889 on Base, with over $346M net attacker profit on Solana alone. Reorgs expose a further 2,875 Ethereum victims. Failures trace to order-flow auction and reorg paths on Ethereum, validator then application-layer exposure on Solana, latency races on Tron, and a documented Base RPC pool leak plus predictable victim behavior. Artifact: No-Place-to-Hide.
Authors: Lioba Heimbach, Ozan Solmaz, Burak Öz, and Christof Ferreira Torres (paper, pdf, No-Place-to-Hide). Lioba Heimbach: GitHub, X, LinkedIn. Christof Ferreira Torres: GitHub, X, LinkedIn.
OllamaDrama: honeypot measures real attacks on exposed Ollama
OllamaDrama introduces Ollure, a low- and medium-interaction honeypot that emulates the unauthenticated Ollama API without a backend LLM. Four deployments across cloud and university networks ran for 84 days and logged 290,887 interactions from 2,793 unique source IPs.
This matters because self-hosted LLM gateways are easy to leave open on the public internet. Prior scans count exposed endpoints; this deployment shows what attackers actually try once they find one.
Most traffic is discovery, fingerprinting, and model enumeration. Beyond scanning, the authors observe model-management abuse, path traversal (CVE-2024-39722) and SSRF (CVE-2026-85180) probes, RCE and XMRig mining via modelfile injection, resource exhaustion, prompt and system-info extraction, and agent-oriented tool-use attempts against the emulated API. Code and a pseudo-anonymized dataset are released with the paper.
Authors: Karina Elzer, Niklas Netterstrøm Johansen, and Emmanouil Vasilomanolakis (paper, pdf, Ollure). Emmanouil Vasilomanolakis: X, LinkedIn.