1. Home
  2. Blog
  3. Alex Vance

Alex Vance

3 postsf4e0c710-4cdb-47d3-9229-b0f1771cab11
MCPAI security

MCP Tool Poisoning: How the AI Agent Protocol Became a Supply Chain Attack Surface

The MCP protocol connects AI agents to over 10,000 tools. It also creates a new supply chain attack surface: poisoned tool descriptions that silently hijack agent behavior. Here's the data, the CVEs, and what to do.

Alex Vance
Jul 21, 2026
prompt injectionAI security

Prompt Injection Defense in 2026: What Actually Works When Detection Is Impossible

OpenAI says perfect prompt injection detection is still unsolved. Three academic proofs show why it may never be possible. This is the defense-in-depth architecture that actually works in 2026.

Alex Vance
Jul 21, 2026
slopsquattingsupply chain

Slopsquatting: When AI Hallucinations Become Supply Chain Attacks

AI coding assistants hallucinate package names 19.7% of the time. Attackers register those names on npm and PyPI before real packages can claim them. Tens of thousands of developers have already installed malicious packages their AI suggested. Here is how the attack works, what the research shows, and how to stop your team from becoming the next victim.

Alex Vance
Jul 21, 2026
  1. Home
  2. Blog
  3. Alex Vance

Alex Vance

3 postsf4e0c710-4cdb-47d3-9229-b0f1771cab11
MCPAI security

MCP Tool Poisoning: How the AI Agent Protocol Became a Supply Chain Attack Surface

The MCP protocol connects AI agents to over 10,000 tools. It also creates a new supply chain attack surface: poisoned tool descriptions that silently hijack agent behavior. Here's the data, the CVEs, and what to do.

Alex Vance
Jul 21, 2026
prompt injectionAI security

Prompt Injection Defense in 2026: What Actually Works When Detection Is Impossible

OpenAI says perfect prompt injection detection is still unsolved. Three academic proofs show why it may never be possible. This is the defense-in-depth architecture that actually works in 2026.

Alex Vance
Jul 21, 2026
slopsquattingsupply chain

Slopsquatting: When AI Hallucinations Become Supply Chain Attacks

AI coding assistants hallucinate package names 19.7% of the time. Attackers register those names on npm and PyPI before real packages can claim them. Tens of thousands of developers have already installed malicious packages their AI suggested. Here is how the attack works, what the research shows, and how to stop your team from becoming the next victim.

Alex Vance
Jul 21, 2026
HOL LogoHOL
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.