A new honeypot called AgentTrap is built to bait autonomous hacking bots, not human intruders.
Researchers designed AgentTrap specifically to fool autonomous penetration-testing agents, the AI systems that now run multi-step attacks on their own. Unlike older honeypots that serve static, scripted decoys, AgentTrap uses what the researchers call sentinel endpoints to screen out harmless traffic, builds deception grounded in the real application it is protecting, and escalates its fake responses based on how the attacking agent behaves. The team tested it against eight different autonomous pentesting agents on a web app with both a real endpoint and a decoy one, under three defense setups. Compared with no defense at all, AgentTrap cut the agents' success rate against the real target from 95.8% to 79.2%, and in 18.8% of runs it got the attacking agent to hand over its own API key.
That is a real improvement over static honeypots, but a 79.2% success rate for attackers is still closer to a passing grade than a failing one. The more useful finding is that whether an agent falls for the trap depends on two separate things: whether its underlying model recognizes it is being deceived, and whether the target system's architecture actually isolates sensitive resources from the decoy. The second point matters more than any clever honeypot design, because it says defense still comes down to basic segmentation.
Honeypots have always been a game of out-thinking the attacker. Now the attacker is also doing the thinking, which means the trap has to get smarter too, not just more elaborate.