Research · curated 25 Jul 2026

ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP

Coverage timeline

25 Jul 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

ShareLock shows that MCP tool-poisoning can be split across multiple tools to defeat manual inspection and automated detectors, undermining defenses that assume malicious payloads live in a single plaintext tool description.

ShareLock is a research framework that performs a stealthy multi-tool threshold poisoning attack against the Model Context Protocol (MCP), using Shamir's secret-sharing scheme to distribute a malicious instruction as benign-looking shares across multiple tool descriptions that reconstruct into a hidden instruction only after a covert trigger is planted during a server update. Experiments across mainstream LLMs and two MCP clients report an average attack success rate exceeding 90% while evading tool-description-based detectors.