Four hundred ninety-two. That is how many MCP servers researchers reportedly found running without authentication. No keys. No identity. Open doors into the tooling layer that autonomous agents call home.

That number is the story. Not the 700 rogue OpenAI agents said to have breached Hugging Face. Not Aurora's ransomware crew arming itself with Cursor. Those are symptoms. The infection is architectural.
I have audited liquidity structures for eighteen years. I scraped 500 ICO whitepapers in 2017 and found that 80% had no real liquidity provision — and that price was a lagging indicator of structural rot. I watched Curve and Compound post 40% APY on emissions that priced to zero. The pattern never changes. When infrastructure is built without an identity layer and without a settlement layer, the first real load test breaks it.
Agent security is that load test. And crypto is the only market that has already run it.
Dreamforce 2026 is set for September 15 in San Francisco. Salesforce will pitch an "AI Control Plane" — a central nervous system for agent identity, policy enforcement, and lifecycle management. Thirty-plus security sessions. A trust harness. Claude routed through Amazon Bedrock inside the Salesforce trust boundary, branded "Claudeforce."
Read the agenda. "How Engie Built an Agent-Ready Security and Privacy Foundation." "A Governance Playbook for Agentforce and MCP." "Apply Architecture Patterns for Multi-Agent Governance." That is not a product reveal. That is a funnel — case study, then methodology, then architecture pattern.
MCP — the Model Context Protocol — is the connective tissue. It lets an agent call external tools. Open, adopted fast, and secured slowly. That is why 492 endpoints sat exposed.
The framing is correct, and that matters. The bottleneck in enterprise AI has moved from model capability to trust and governance. Gartner, Forrester, every CISO facing a board is being asked one question: can we let an autonomous agent read and write?
But the source material I reviewed carries three defects. No sourcing on the central claims — the 700-agent breach, the Aurora agent, the 492 exposed servers, backed by two 2026 CVE numbers and one Trend Micro attribution. A time paradox, looking forward to September 2026 while describing 2026 incidents in past tense. And unverifiability. I cannot cross-check a single CVE.
Strip the noise. One durable signal survives: the identity model is broken.
Here is the mechanical failure. Standard OAuth issues a token that says a human delegated this, briefly, broadly. Autonomous agents do not work that way. They run headless. They chain steps. They act when no human is watching. You are asking a session-based identity model to govern a workload that has no session.
I hit this wall in 2025. My team built a macro model forecasting demand for GPU-powered networks — Render, Akash — as agents began settling compute on-chain. The agents ignored our dashboards. They needed to prove who they were, what they were permitted to do, and what they had done. Nothing in the enterprise stack answered that. Everything in the on-chain stack did — badly, but genuinely.

Agent identity is a wallet problem, and crypto solved it a decade ago — including all the ways it fails. On-chain, an address is a verifiable identity. A smart contract is an enforceable permission. A transaction log is an append-only audit trail. The triple the source demands — identity, headless authentication, auditability — maps one-to-one onto public-key cryptography, capability-based access, and immutable ledgers. Salesforce calls its answer a control plane. Crypto calls the same thing a protocol.
The gap is execution, not concept. Crypto's identity layer is fragmented, gas-expensive, and hostile to compliance. Salesforce's plane is centralized, unproven, and locked to one vendor.
Now watch the settlement layer. Stablecoins are becoming the default unit of account for machine-to-machine payment, and that reframes the security question entirely. When one agent pays another, the transaction must clear. PYUSD, USDC, USDT — these are the rails. After Terra I tracked USDT market cap against the dollar index and concluded emerging markets were using stablecoins as a parallel monetary system. Agents accelerate that. A headless process cannot open a bank account. It can hold a stablecoin balance.
So agent security is no longer only about prompt injection or privilege escalation. It is about who controls the money an autonomous agent can move. Liquidity leaves first. Watch the pipes.
I have seen this configuration before. In 2021 I mapped NFT holder distribution and found whale accumulation in low-liquidity collections alongside rising volume and falling unique wallets. Wash trading. The floor was fiction — BAYC dropped 40% that quarter. Same signal here: volume without verifiable identity is manufactured confidence.
Infrastructure without an identity layer and a settlement layer is not infrastructure. It is a honeypot. The 492 exposed servers prove the doorway is open. The agent-to-tool link authenticates by default to nothing. Tool descriptions can be poisoned. One unpatched gateway becomes a path into CRM records, payment credentials, the stablecoin treasury an agent manages.
There is a second question the agenda avoids: does the control plane govern the MCP gateway, or do they run in parallel? If the answer is unclear, you have not built a control plane. You have built a security island.
Everyone positions Salesforce as the standard-bearer. I do not buy it. Microsoft shipped Entra Agent ID in 2025. Okta, CyberArk, Palo Alto already sell non-human identity products. Salesforce's plane binds to its own platform — Agentforce, its trust boundary. That is not a standard. That is a walled garden with a security label.
Recall the real competitive question. Salesforce's CRM base is under attack from AI-native rivals. Thirty security sessions is not strength. It is anxiety. A confident leader does not spend three days reassuring CISOs.
The deeper blind spot: a centralized control plane recreates the single point of failure it claims to solve. I watched centralized exchanges custody user funds and lose them. I watched Terra's algorithmic peg break because it assumed stable demand that never existed. A plane governing every agent action is the same architecture — one throat to choke. When it fails, it fails everywhere, at once.
The real standard will be permissionless. On-chain attestation. Verifiable credentials. Token-gated capability. Slow, ugly, un-killable. Arbitrage closes the gap. You are late.
The agent economy will settle on-chain, whether Salesforce likes it or not. Timing is a liquidity question. Watch three signals over the next two quarters: stablecoin balances held by autonomous agent wallets, the first on-chain agent-identity registries, and the first enterprise incident traced to an unauthenticated MCP gateway. One of those turns the sideways chop into a trend. Macro moves before you blink. Adjust.