Story · arXiv
Agent Name Collision Attacks in Multi-Agent Systems (arXiv)
paper · Story page

An agent card's name is metadata in A2A, with no collision semantics defined for it. Six of seven pinned open-source integrations still treated it as a local routing identifier, sending a request addressed to a trusted peer to an attacker-controlled one.
In plain words
- Researchers found that attackers could impersonate trusted artificial intelligence assistants by copying their names.
- Some systems used these names to decide where to send requests, even though names were only meant as readable labels.
- In six tested systems, requests intended for a trusted assistant went to one controlled by an attacker.
- Users risked sending requests to the wrong recipient, although tests found no direct transfer of the trusted assistant's access details or tools.
Appeared in
- Forged control tokens blank an agent's reasoning while the tool call still fires
Sep 25, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
