Skip to content

Security1 publisher2 min readPublished

OX Security scan of 15,465 MCP servers puts vetting on the companies installing them

OX Security scanned 15,465 public MCP servers in five registries and found no marketplace review or guardrails. Six of the listed servers sit on expired domains anyone can register for $4 to $12 a year, and a buyer would inherit the agents still calling them.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying OX Security scan of 15,465 MCP servers puts vetting on the companies installing them
Generated illustration

What happened

  • After deduplication to 5,095 hostnames, 15.6% resolve to infrastructure outside the United States, including 19 in China and 18 in Russia.
  • OX says an operator could launch a server on a clean US IP address and later route its traffic somewhere else.
  • About 0.45% route through consumer tunneling services, mainly ngrok-free, and OX says these run from personal machines and likely home networks.
  • OX says the code behind a remote MCP server can be wholly unlike the code published in its public repository.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Agents configured against a listed server keep calling its hostname after the operator lets the domain lapse, so whoever registers it next receives that traffic.
  • decision Teams that put cloud adoption through residency rules, Zero Trust boundaries and IAM now have to decide whether MCP endpoints get the same review, since OX says they often sit outside it.
  • constraint Approving a server on its location or its public repository can go stale after sign-off, because the operator can move traffic and the backend can differ from the published code.

Ranked by what an attacker can do today, the expired domains come first. At the prices OX quotes, registering all six would cost $24 to $72 a year [19]. OX wrote that the buyer would take over the server's established identity and receive requests from every agent still set up to call it [9]. Receiving that traffic needs no flaw in the protocol or in the agent. Stopping it costs the defender an inventory of MCP hostnames in agent configurations, checked against DNS.

The six sit inside a larger set. Another 2.3% of hostnames no longer resolve, about 117 endpoints out of 5,095 [7][20]. The 15,465 raw listings come to roughly three per unique hostname [24].

The foreign-hosting figure is a governance problem. The non-US share works out to about 795 endpoints [22]. China and Russia together account for 37, about 0.7% of the deduplicated set [21]. According to OX, an agent using these servers may move data into jurisdictions that security teams never signed off on [5]. The tunnel group is the smallest share in the report, about 23 hostnames [23].

Vetting by the installer has its own limit. "Code review tells you what the developer published, not what the server runs," wrote Moshe Siman Tov Bustan, Security Research Team Lead at OX Security [11][17]. The team made the same over-trust argument about GitHub repositories in a talk at RSAC and OWASP last year [13]. Across the most popular marketplaces, Bustan wrote, the team found "no guardrails and no review" [2]. His comparison is Google's Bouncer, the 2012 scanner that checked Android apps for malware before they reached users; MCP marketplaces have no equivalent, and anyone can publish a server [12].

These findings come from a contributed article by a security vendor [17]. Its methodology, a prompt-injection proof of concept and the threat scenarios sit in a separate downloadable report [18]. The article does not name the five registries, a threat actor, or any observed abuse of a dead domain. It is OX's second MCP study this year: earlier, the team traced critical vulnerabilities in Anthropic's MCP source code, downloaded more than 150 million times [15].

"Until marketplaces add vetting, code signing, and origin verification, the enterprise has to do that work," Bustan wrote [16].

What to watch

  • Whether any of the five registries adds the vetting, code signing or origin verification OX names as missing.
  • Registration of any of the six expired domains by a new owner, and whether OX's full report identifies them.
  • Whether OX names the five registries, so other researchers can reproduce the 5,095-hostname count.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories