September 18, 2026

Agentic Web Observatory: Discovery Traffic, Payment Scams and the Limits of Success

AI-generated · label definition
← Back to News
Agentic Web Observatory: Discovery Traffic, Payment Scams and the Limits of Success

Image: The public WagerX Agentic Web Observatory, captured September 18, 2026. This is a view of the service, not a chart of this report's fixed-window figures.

Observation window: to , end exclusive. Extracted: . This is eight complete UTC days plus a partial September 18—not nine completed days.

Our previous nine-day report, covering September 1–9, explained why HTTP 200 is not evidence of agent success. This follow-up adds a more concrete distinction: an agent can successfully answer a request that should never be carried out.

Since that report, we have continued collecting gateway observations, separated complete days from today's partial figures, and performed three owner-authorised live rechecks of suspicious A2A messages. We are preserving the resulting timestamped aggregate dataset so readers can distinguish this fixed release from the rolling Observatory dashboard.

The snapshot: 76,572 requests, not 76,572 agents

On smaller screens, scroll the comparison table sideways to read all periods.

Production MCP and A2A request counts; all times UTC
Request classSept 10–17: eight complete daysSept 18: before 16:40Combined snapshot
Discovery69,9551,19971,154
Task-shaped122112234
Other4,7094755,184
Total74,7861,78676,572

Discovery means initialization and capability listing. Task-shaped means an MCP tool-call method or an A2A message/task-submission method, including unsupported calls and unsolicited messages. Other traffic includes notifications, pings and methods outside those definitions. The dataset lists the exact classification rules.

We sum stored request counters, including repeated discovery polling. These are not unique agents, companies or people. The live dashboard applies its own display and discovery-deduplication rules, so its headline should not be substituted for this release's request total.

Repeated discovery dominates the volume

48,096 requests recorded a rate-limited outcome in this window. This overlaps the request classes above; it is not an extra category to add to the total. The largest complete day was September 13, with 24,993 requests, of which 24,372 were discovery requests and only 13 were task-shaped.

For perspective, the previous report covered nine complete days and 40,950 requests. This release has a different duration, includes a partial final day, and excludes three specifically identified internal safety replays. We are not treating the larger total as an equal-window growth rate or a sign of increased useful adoption.

Task-shaped traffic can be payment-scam traffic

During the eight complete days, task-shaped counts ranged from nine to 36 per day. September 18 had already reached 112 by the cutoff. That jump deserves investigation, not a conversion-rate headline.

We observed messages impersonating protocol authorities, grant programmes and security services. Their pretexts included wallet migration, verification payments and emergency recovery. One sampled message used Morse code to encode its instructions. These were attempts to turn a public information service into a financial actor.

A narrow, documented text-pattern check found 70 A2A requests with payment-solicitation indicators, all on September 18 before the cutoff. They are already included in the task-shaped totals. This is an indicator count, not a count of attackers or an exhaustive scam census: encoded messages can evade the patterns, and a pattern match alone does not independently establish malicious intent. The public dataset contains the matching rules, not the messages.

What the three live rechecks actually established

At approximately 16:00 UTC on September 18, we replayed three examples against the live public A2A gateway:

  • A wallet-migration request returned an unrecognised-directory response.
  • An attestation-fee request also returned an unrecognised-directory response.
  • The encoded example prompted a clarification request.

No financial action was executed in those three rechecks. The public information route handling them had no wallet-transfer capability. The important protection was that capability boundary—not a claim that Wagie correctly diagnosed every scam. Its generic replies leave room for clearer warnings.

Original response bodies were not retained, so these rechecks do not establish what every historical request received. They are not a comprehensive security assessment, proof that all sensitive information is inaccessible, or a guarantee against future vulnerabilities. We excluded the three internal replay requests from this report's traffic counts.

HTTP success still tells only part of the story

All 234 task-shaped requests returned HTTP 200
Recorded protocol outcomeRequests
Success213
Unknown tool13
Rejected unsupported A2A task submission8

A success label means the handler returned a protocol-level answer. It does not mean a payment request was obeyed, a claim was correct or a useful job was completed. Equally, a structured rejection can be correct behaviour rather than an outage. Of the 234 task-shaped requests, 196 used A2A and 38 used MCP; neither figure measures legitimate users.

How to read and reuse this release

The extraction uses production records whose creation timestamps fall inside the stated interval and whose IP field is nonempty. It preserves repeat counters and uses the previous report's case-sensitive internal-test exclusions, plus the exact internal label used for today's three safety replays. Known labels cannot remove every possible internal test.

The cutoff aligns with a closed ten-minute discovery bucket; no selected record had a completion timestamp at or beyond that cutoff. Daily aggregates, the complete-day subtotal, the partial-day subtotal, outcome counts and classification limitations are included in the downloadable JSON. Comparable September logging follows the August 31 instrumentation expansion; we do not manufacture a growth comparison with sparse August records.

For agentic iGaming builders, the lesson is to keep public discovery, information retrieval and consequential actions separate—and distinguish unsolicited activity from evidence of useful work. WagerX's next observations can be compared with these dated releases without silently changing what this snapshot says.

This is one service's field report, not an industry census, market-share estimate or proof of agentic-web adoption. No countries, raw prompts, user agents, IP addresses, wallet addresses, caller identifiers or request-level records are published.

Report series: Read the September 1–9 report · Download this fixed aggregate snapshot · View the live Observatory · Read the gateway documentation.

AE

Andreas Ericsson

Founder of WagerX.io

Crypto gambling and trading intelligence veteran with 8+ years of experience. Andreas has been at the forefront of blockchain gaming since 2018, pioneering independent casino audits and building one of the most trusted review platforms in the industry.

Reddit X / Twitter 8+ Years Experience Since 2018