TL;DR
gadgethumans-mcp, an npm package, tells developers it will let their AI agent "auto-sign" x402 micropayments. According to an analysis by Knostic Labs [1], instead of signing locally it puts the configured wallet private key, unchanged, into an HTTP header and sends it to its publisher's server on every recognized tool call. SignWarden did not run the package. We later performed an internal static scan without executing it.- It was downloaded 2,648 times between July 1 and September 28, 2026 [2]. Downloads are not installs, and no stolen funds or victims have been identified [1].
- As of 2026-09-28, all 10 versions are still on npm and none is deprecated [3].
- If you ever configured a key with this package, treat that key as compromised and move your assets to a new wallet.
Incident card
| Field | Value |
|---|---|
| SignWarden ID | SW-MCP-2026-000006 (1.0.3), SW-MCP-2026-000007 (1.0.9). SignWarden flags versions 1.0.3 and 1.0.9 (named in Knostic's analysis); 1.0.8 under review; other versions not assessed |
| Public analysis | 2026-09-08, Knostic Labs [1] |
| Ecosystem | npm / MCP server |
| Protocol | x402 (machine-to-machine payments) |
| Versions on npm | 1.0.0–1.0.9 (10 versions); latest 1.0.9, published 2026-08-02 [3] |
| Downloads | Jul 1,152 · Aug 1,175 · Sep 1–28 321 [2] |
| Loss | None known [1] |
| Technique | Malicious MCP server / private-key exfiltration |
| Failed layer | Tool supply chain; key management |
Timeline (UTC)
| Time | Event | Source |
|---|---|---|
| 2026-07-01 20:45 | 1.0.0 published; 1.0.1–1.0.3 follow the same day | [3] |
| 2026-07-03 | 1.0.4 and 1.0.5 published | [3] |
| 2026-08-02 08:17 | 1.0.9 published and tagged latest | [3] |
| 2026-09-08 | Knostic Labs publishes its analysis | [1] |
| 2026-09-28 | SignWarden reports the package to npm | SignWarden |
| 2026-09-28 | All 10 versions still on npm; none deprecated | [3] |
How it works
Steps 3–4 are based on Knostic Labs' analysis [1]; SignWarden did not run the package, and later performed an internal static scan without executing it.
- The pitch. The package says that once a wallet private key is configured, the agent handles x402 payments "without any manual steps" [1].
- Setup. A developer puts the key in an environment variable and connects the MCP server to their agent.
- Exfiltration. According to Knostic [1], on every outbound request for a tool call it recognizes, the package copies the raw key into a custom HTTP header and sends it to its default endpoint on
gadgethumans[.]com[1]. - Result. Per the same analysis [1], the server receives a key that controls the entire wallet, not a single-use payment signature. No signing happens locally [1].
We do not reproduce the package's code.
Why this matters
x402 is built so that clients send signatures, never keys [1]. "Auto-signing" implies the key stays on your machine. Here, the phrase covers the opposite.
The deeper problem is where MCP servers run. They share the agent's environment and can read the same variables. Agent frameworks today don't restrict which tool can see a secret. And neither npm nor MCP directories check whether a package sends secrets off the machine: this one stayed downloadable for weeks after a public write-up [1][3].
Where it could have been stopped
| Control | Why it didn't stop it | Effect if present |
|---|---|---|
| Keep keys out of the agent environment (wallet-provider signing API or scoped permissions) | The package asked for the raw key | The package never sees the key |
| Outbound allowlist for MCP servers | Any outbound connection allowed by default | Requests to unknown domains blocked |
| Pre-install scanning of MCP packages for secret egress | None | Flagged before install |
| Capped, expiring permissions instead of keys (e.g. ERC-7715) | Not used | A leak has a ceiling |
What to do
- If you installed
gadgethumans-mcpand set a key: rotate the key now and move your assets. - Treat any MCP server or agent skill that asks for a raw private key as high-risk.
- Give agents a wallet provider's signing API or scoped permissions; keep private keys out of environment variables.
- Fund agent wallets with only what a task needs.
- Put MCP servers behind an outbound allowlist and log every outbound request.
Open questions
- Whether the other versions on npm also send the key. SignWarden flags versions 1.0.3 (SW-MCP-2026-000006) and 1.0.9 (SW-MCP-2026-000007), named in Knostic's analysis [1]. Our static scan found that the JavaScript in 1.0.8 is identical to 1.0.9; 1.0.8 is under review. The remaining seven versions have not been assessed.
- Whether anyone lost funds; there is no evidence so far [1].
- Whether the publisher has responded. SignWarden reported the package to npm on 2026-09-28; no reply as of publication.
Sources
- Knostic Labs, When auto-signing sends your wallet private key to a remote server, 2026-09-08.
- npm downloads API, range 2026-07-01 to 2026-09-28, queried 2026-09-28 22:34 UTC.
- npm registry, gadgethumans-mcp, queried 2026-09-28 22:34 UTC.
This write-up is based on public information and is provided for informational and research purposes only. It is not investment, legal, or security-assurance advice. Figures may be revised as new data emerges. No exploit code is included. If you are a party to this incident and have corrections, please contact SignWarden at security@signwarden.com.