zerofox logo
Blog

The AI Agent Attack Surface Is Growing Faster Than It Can Be Monitored

by Peter Lowe
The AI Agent Attack Surface Is Growing Faster Than It Can Be Monitored
7 minute read

GoDaddy recently launched the Agent Name Service registry (the ANS), which provides a directory of registered AI agents. Other registries such as GLAMA, Smithery, and the MCP registry (a list of servers providing interfaces for AI agents) have already been providing directories for agent discovery. And at least 2 proposals for DNS-based agent name registration have been put forward: DNS-AID and DNSid. Taken together, these show that the proliferation of AI agents is expanding at a huge rate, and doesn’t show any signs of slowing down.

This is a fascinating and fast-developing attack surface to investigate, so let’s take a look.

One Quick Example

There's an AI customer support agent currently registered that claims to work for Zelle, except its display name isn't "Zelle" - it's idjory[@]icloud.com. It sits on a platform called helpagent[.]club, which seems to be a domain provided by GoDaddy for agents to live under. It was registered on May 27, and it advertises that it can look up your orders and resolve your account issues. Searching for this email finds an Instagram account with the name iledelatortue.0rg and posts with the #CashApp hashtag. 

It's a pretty crude example of an agent that’s clearly not exactly legit, but it shows how easy it is to get into an “authenticated” registry, and the infrastructure being built around agents like it raises the stakes considerably, as we’ll talk about below.

What the Scan Covers

For the past few weeks we’ve been running continuous scans against the public places where AI agents and MCP servers announce themselves. These fall into two kinds. The Agent Name Service (ANS) is the naming and identity layer. It’s a PKI-based scheme operated by GoDaddy, that gives an agent a resolvable name and, optionally, a certificate proving domain ownership. Sitting on top of that are the discovery registries mentioned earlier like GLAMA, Smithery, and the MCP registry, which index agents and servers and let other software find them. As of the time of writing that inventory holds around 223,000 distinct agent names, 174,000 of them registered through ANS, alongside roughly 33,000 GLAMA servers and nearly 16,000 MCP registry entries. There are also a few agents discovered by simply looking for DNS records matching the schemes proposed by DNS-AID and DNSid.

The most important thing to consider here: these are registered agents, and registries are opt-in. Every figure here counts only the agents that chose to be listed. The unregistered population is covered further down.

Growth Rate

Over a three-week window in June, the ANS agent count climbed from about 95,000 to about 150,000— roughly 2% growth per day—and it hasn't stopped.

For comparison, malicious domain registration—the surface most in brand protection have watched for years—has never grown like this, because a domain has at least a little friction: you need a registrar, a payment, DNS, and somewhere to point it. Even with those barriers, domains are one of the most common attack surfaces that’s being exploited. Getting an agent listed has far fewer. The optional PKI verification described above is the only real gate, and nothing stops an unverified agent from being registered and named after whatever brand its operator likes. The agents themselves are described as decentralized, but in practice they route through a shared endpoint host (more on that below) so the naming is cheap and the hosting is someone else's problem. Whatever you believe about how useful these agents actually are, the cost to stand one up and claim a brand's name is close to zero, and the data shows people are doing it at scale.

Concentration on Two Platforms

Of the 174,000 ANS agents, helpagent[.]club accounts for more than 94% at 163,500 of them. These seem to be the free domain offered by GoDaddy (there’s another subdomain, aipro.godaddy[.]com which appears to be for premium customers - again, not much documentation visible here). Add agenthost[.]club at just over 5% and two platforms hold about 99.5% of every registered ANS agent we can see. Each agent gets its own support-<uuid>[.]helpagent[.]club endpoint, so the names look distinct, but they all resolve back to the same second-level domain. Whatever "decentralized" is meant to imply, the routing doesn’t seem to be that.

It also tells you something about how the abuse is produced: the flagged Zelle agent's full host is support-88a5f216-976f-4acd-bca1-784bc73f0c5a[.]helpagent[.]club, and you can see similar subdomains for a Microsoft agent, a USPS agent, a DHL agent, and an IRS agent, among others. These are surely not real agents signed up from major organizations using GoDaddy’s free service.

The impersonation targets are concentrated in finance and government: Zelle, Cash App, U.S. Bank, Citibank, USPS, DHL, IRS, Social Security. Exact-string brand matches, several of them registered in the last 24 hours.

The Connection to Payments

On its own, an agent like this is a limited threat while it's only interacting with humans, because a person can look at idjory[@]icloud.com and recognise that something is off. What changes the picture is that, over the last year, the payments industry has invested heavily in letting agents transact with each other and with merchants directly, without a human approving each step.

Visa's Intelligent Commerce program shipped a protocol-agnostic on-ramp in April 2026 that accepts agents across Visa's Trusted Agent Protocol, Mastercard's rails, OpenAI and Stripe's ACP, and the Google/Shopify UCP standard at the same time. Google's Agent Payments Protocol launched in September 2025 with more than sixty partner organizations, including Mastercard, PayPal, Coinbase, and American Express. Coinbase's x402 settlement layer had, by April 2026, processed around 165 million transactions across roughly 69,000 active agents.

The trust boundary has moved. Where it used to be a human looking at a screen and deciding whether something felt legitimate, increasingly it's one piece of software deciding whether to trust another based on a registry entry and a protocol handshake. There's a verification layer meant to hold that boundary, but it's optional, and our data shows the registries are full of unverified entries impersonating exactly the brands—banks, payment apps, government services—where a fraudulent transaction pays off. An impersonation agent is no longer a lure waiting for a click; it's a participant, positioned to be discovered and invoked inside an automated flow with a payment credential attached to it.

The Unregistered Population

Every agent in the scan opted in to being listed, and that's the visible surface. The larger population never registers anywhere public: internal enterprise agents, self-hosted MCP servers, the short-lived agents spun up and torn down inside chat surfaces, wallet-connected agents built for a single purpose. There's no registry to scan for those.

The MCP registry indicates where this is heading. Its flagged entries already include wallet managers, treasury tools, cross-border banking connectors, and a notable number of servers with "verified" or "official" in the name - trust-laundering, the same technique as a phishing page copying a bank's logo, applied to a machine-readable listing.

We can't measure the unseen population directly, but given how these agents are deployed, the ratio of unseen to registered isn't small.A conservative floor sits somewhere around five to one, and the realistic band runs higher.

Projections: 3 Months and 12 Months

Forecasts in this space age badly. Still, starting from the observed growth curve, which is steep but visibly decelerating, it's already flattening in the most recent scans. A simple exponential fit produces something like 200 million registered agents in a year, which is clearly nonsense. Instead we applied a decaying month-over-month growth rate and combined it with public agentic-commerce adoption data.

Treat these as ranges with stated assumptions, not predictions:

HorizonVisible (registered)Total surface (visible + unseen)
Today~154k ANS / ~200k indexed-
+3 months~375k - 610k~2M - 10M
+12 months~1M - 4.4M~6M - 70M

The assumptions here are an initial monthly growth of 45-70% that goes down each month rather than compounding flat, and an unseen-to-visible ratio of roughly 5x to 15x. But the point of the range is not precision. It’s that even the conservative floor,a few million agents inside a year, most of them unmonitored, an unknown fraction impersonating someone, is a surface no brand protection program is currently built to cover.

Conclusion

The main takeaway here is that this attack surface is real, expanding rapidly, and that nobody is monitoring it very well. The hidden side is ripe for exploitation with the risk massively increasing as payments become more common online, official AI agents are easier to impersonate, and people’s perceptions of AI agents are shifting from an annoyance to an everyday part of life.

A note from the author: This post only really covers one aspect of the growing wave of AI agents, and doesn’t delve too deeply into the many other areas that are being affected. Trust boundaries, malvertising, exploitation of AIs at scale, Trust & Safety maturity, or anything else: look out for future posts exploring those topics.

Peter Lowe

Peter is our Threat Research Lead in the Signals Research Program at ZeroFox, working on ways to improve our disruption efforts and coverage of the threat research landscape.

Peter’s career spans over 30 years, and he currently acts as the DNS Abuse Ambassador for the Forum of Incident Response and Security Teams (FIRST) as well as the co-chair of the DNS Abuse SIG. In his spare time, he runs one of the most popular blocklists for ads and trackers, and is active across a range of industry groups and efforts.

Tags: Artificial IntelligenceDomain Protection