MCP Rug Pull

Many MCP clients ask users to approve a server once, then trust it indefinitely. A rug pull exploits that one-time approval: the server updates its tool descriptions or logic later, and the agent keeps using it without fresh review.

Rug pull patterns include:

  • Definition swaps: Tool descriptions updated to include hidden instructions.
  • Behavior changes: Server code altered to exfiltrate data or misuse credentials.
  • Delayed activation: Malicious logic that triggers only after a period of normal use.
  • Package updates: Compromised new versions pushed through public registries.
  • Ownership transfer: Popular servers sold or hijacked, then weaponized.

Because MCP servers often hold tokens for email, code repositories, or databases, a rug pull can quietly convert a trusted integration into a data theft tool.

Defenses include pinning server versions, hashing and monitoring tool definitions for change, re-approving servers after updates, and routing MCP traffic through a gateway that enforces policy.

How PointGuard AI Helps

The PointGuard AI MCP Security Gateway tracks tool definitions and blocks unapproved changes, so a server that alters its behavior loses access until it is reviewed again. AI Discovery maintains an inventory of MCP servers and versions in use.

Learn More

Watch Blog Video

Follow us on LikedIn

Our Newsletter

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.