Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$76,422.5 -2.80%
ETH Ethereum
$2,422.14 -3.93%
SOL Solana
$99.22 -3.08%
BNB BNB Chain
$719.1 -0.62%
XRP XRP Ledger
$1.39 -1.44%
DOGE Dogecoin
$0.0817 -2.95%
ADA Cardano
$0.2019 -4.04%
AVAX Avalanche
$7.44 -0.77%
DOT Polkadot
$0.9849 -2.85%
LINK Chainlink
$11.28 -1.90%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$76,422.5
1
Ethereum
ETH
$2,422.14
1
Solana
SOL
$99.22
1
BNB Chain
BNB
$719.1
1
XRP Ledger
XRP
$1.39
1
Dogecoin
DOGE
$0.0817
1
Cardano
ADA
$0.2019
1
Avalanche
AVAX
$7.44
1
Polkadot
DOT
$0.9849
1
Chainlink
LINK
$11.28

🐋 Whale Tracker

🟢
0x77d7...7062
3h ago
In
4,742.74 BTC
🟢
0xf54c...a6ed
2m ago
In
2,267,123 USDC
🔵
0xecb9...bfbb
5m ago
Stake
1,380,683 USDC

💡 Smart Money

0x66ae...80bd
Early Investor
+$1.5M
64%
0x6388...f753
Experienced On-chain Trader
+$1.6M
95%
0x43a3...4c66
Experienced On-chain Trader
+$3.6M
93%

🧮 Tools

All →
Research

Snowflake Just Turned MCP Into Enterprise Infrastructure. The Attackers Already Knew.

CoinCat
We didn't see a product launch. We saw a defensive concentration event. Snowflake's new Cortex AI Gateway is being described, in the polite language of enterprise press releases, as a way to enforce identity, policy, and audit at the tool-call layer for AI agents. That is accurate as far as it goes. But the deeper story is not about Snowflake. It is about who owns the intersection between the emerging Model Context Protocol and the security perimeter. The answer is still in motion, and the attackers are already moving faster than the governance layer can catch up. We didn't need a security audit to know that something was wrong. We needed a calendar. In the same 72-hour window that Snowflake was formalizing its gateway story, two massive acquisitions closed: Cyera agreed to buy Oasis for roughly $1 billion, and Okta moved to acquire Permiso for about $200 million. Both are MCP-adjacent identity security plays. Meanwhile, the NadMesh botnet has publicly designated MCP as a preferred attack surface. And the first major MCP-related intellectual property dispute, Runlayer v. Rippling, has been filed in the Southern District of New York. Any one of these facts would be noteworthy. Together, they mean the enterprise gateway layer has become the new front line. This article is not an obituary for the hype cycle. It is a wiring diagram. Based on my experience sitting through the 2022 DeFi audit race, when protocols were shipping code faster than security teams could read it, I can tell you the pattern: infrastructure wins, security loses, then everyone panics and buys a gateway. The problem is that the gateway itself is becoming a single point of failure. We are building a toll booth for agent traffic. And everyone wants to own the toll booth. In a sideways market, where token prices chop and attention spans shrink, the real money is quietly moving into infrastructure. The last few weeks confirm that pattern. The MCP gateway is not another SDK. It is a new structural layer of the enterprise AI stack, and Snowflake has decided to claim it first. Context: MCP stopped being a protocol and became a perimeter. Let's rewind. MCP, or Model Context Protocol, is Anthropic's open standard for connecting AI assistants to external tools, data, and workflows. Think of it as the universal adapter that lets an LLM call a CRM API, read a database, trigger a payment, or update a ticketing system. In 2024, that was a neat developer feature. By 2026, it is a mission-critical integration layer. The protocol's latest revision made MCP stateless. The change was described in a project update as the biggest modification since the protocol first launched, with an emphasis on scalability and modularity. That sounds like boring technical hygiene. But statelessness is not merely a design choice. It is a declaration of intent: MCP wants to be the standard for agent interoperability across every enterprise tool. Stateful sessions, which require the server to remember conversation context, are pushed aside for a simpler, more horizontally scalable model. Snowflake's timing is not accidental. The company is sitting on a massive enterprise customer base and reported $1.33 billion in quarterly product revenue. Its data cloud has been the default landing zone for corporate data for years. But data interoperability is now a commodity. The value has moved one layer up, into agent interoperability. If an AI agent can call anything, the company that controls the call layer controls the enterprise AI stack. That is why Snowflake, an organization built on a data warehouse, is now talking about gateways. Gateway infrastructure is the new database. It sounds like an exaggeration. The last few weeks suggest otherwise. Snowflake's Cortex AI Gateway is built around technology acquired through Natoma, an engineering team and product set that Snowflake brought in to create a governable interface between agents and tools. The gateway is not meant to make models smarter. It is meant to make them safer to deploy, to a point. Specifically, it enforces identity, policy, and audit at the point where an agent invokes a tool. That means every API call, every database query, every external action can be checked before it happens and logged after it happens. That is a fundamental shift. Earlier security models treated AI as a model problem. You red-team the prompt, you filter the output, you hope the model doesn't leak data. MCP gateway infrastructure treats AI as an access problem. Who asked for this action? Does that agent have the right permission? Was the tool call authorized? Those questions are not answered by the LLM. They are answered by the gateway. The seven identity partners announced alongside the Snowflake launch are a tell: 1Password, Aembit, Cyera, Linx Security, Okta, SailPoint, and Saviynt. These are not model providers. They are identity and security infrastructure players. Snowflake is not building a co-pilot. It is building a policy enforcement point. The fact that Okta and Cyera appear both as partners and as acquirers in this story shows how fast the landscape is moving. The data cloud narrative is no longer enough. Snowflake spent years selling the idea that data gravity would naturally pull in every analytics workload. That thesis worked until the AI agent arrived. Agents do not want to query a warehouse through a SQL console. They want to call a tool over MCP, get a fast response, and move on. The warehouse becomes one node in a graph of tools. Snowflake needs to be the graph's gatekeeper, not just its storage room. Core: What a Gateway Actually Does, and Where It Breaks. Let me be precise. A gateway in the MCP world sits between the AI agent and the tools it wants to call. When an agent wants to query a database, the request passes through the gateway. The gateway checks the agent's identity against the configured policies, decides whether the tool call is allowed, enforces rate limits and context scoping, and writes an audit record. The response from the tool can also be inspected before it is returned to the model, preventing certain data exfiltration paths. Snowflake's product pitch is centered on this enforcement layer. The company wants to own the point where trust is evaluated. From a cybersecurity perspective, this is the right instinct. I learned that lesson the hard way in 2022, after audited DeFi contracts were still getting exploited because the security model was embedded in the application layer rather than the transaction layer. In agent infrastructure, the same principle applies: if security is only inside each tool, it will be inconsistent. A gateway can centralize the rulebook. But centralization has a hidden cost. Every request now flows through a chokepoint. In a decentralized system, an attacker needs to compromise one MCP server or one tool integration. With a gateway, an attacker who compromises the gateway gains the keys to every tool that the gateway protects. That is a concentration of risk, not just a concentration of governance. The industry is calling this security, but in structural terms it is a vault with a single door. Vaults are secure until someone loses the master key. The statelessness of the new MCP spec adds a subtle complication. Audit trails and policy enforcement are inherently stateful operations. You need to know who did what, in what sequence, with what result. A purely stateless request-response model makes horizontal scaling easier, but it pushes session management, rate limiting, and context tracking into the gateway. That means the gateway is not an optional proxy. It becomes the state holder for an ecosystem that is trying to eliminate state. The tension between MCP's stateless ambitions and the gateway's need to maintain context is the technical fault line no press release will mention. There are also unanswered performance questions. What is the latency overhead of routing every tool call through an external identity check? Can the gateway handle streaming tool calls and streaming audits simultaneously? Is the gateway in the middle of the request path, or is it a sidecar that only intercepts certain events? Snowflake has not published a technical whitepaper with capacity numbers, so we are left to infer. Based on my experience integrating security policy engines into high-throughput systems, the average gateway overhead can be acceptable in a low-volume demo and catastrophic in production when hundreds of agents are making nested tool calls. Then there is the management sprawl question. Enterprise users will not have one MCP server. They will have dozens. Each server may have its own access tokens, API keys, and allowlists. The gateway needs to discover those servers, understand their capabilities, and apply policy before an agent is even allowed to call them. Does the gateway do active discovery? Does it enforce policy through a central registry? Or does it rely on a manual upload of MCP endpoints? We don't know. We do know that MCP server sprawl is a phrase that now exists in security marketing materials, which means the reality is already painful. The same pattern appeared in DeFi during the audit race of 2022. Smart contract teams would buy audits like insurance stamps, then deploy code that still had composability risks. Auditing was treated as an institutional ritual rather than an ongoing process. I see the same ritual forming around agent infrastructure. Companies will purchase a gateway and checklist compliance, but the gateway only works if the policy configurations are complete, the identity sources are synchronized, and the anomaly response team is on call. Those are operational investments, not license fees. There is also a hardening question that no marketing slide can answer. What happens when an MCP server is malicious? The gateway can block a known list of invalid servers, but prompt injection can hide inside a tool response. An attacker can craft a tool result that tells the agent to change its instructions. If the gateway only checks the request-side, it will miss response-side manipulation. The security model has to inspect both directions: the agent's call and the tool's response. Snowflake has not explained how it plans to detect prompt injection in a streaming response from a third-party MCP server. In my audit experience, the failures usually happen at the boundary where data is trusted without validation. The boundary here is the gateway's response filter. The compliance question is just as serious. Enterprise customers will ask: Where are the audit logs stored? How long are they retained? What encryption standards are applied? Does the gateway meet SOC 2, GDPR, and SOX requirements? Without public answers, the gateway is a feature, not a platform. Security teams cannot buy a platform on trust alone. They need artifacts, independent tests, and evidence. The Competitive Stack: Too Many Toll Booths, Not Enough Roads. The gateway segment is already crowded. Snowflake is not entering an empty room. The competitive list reads like a nightmare Venn diagram: API management providers like Kong, agent runtime platforms like Diagrid, dedicated MCP gateway startups like MintMCP, enterprise agent orchestration platforms like Obot, plus TrueFoundry, Lunar.dev, and Arcade. Each of these companies comes at the problem with a different assumption about the stack. Kong is approaching MCP from the API management world. Its thesis is that agent tool calls are just API calls with more context. Diagrid is approaching from the distributed application runtime world, where agent workflows need reliable execution. MintMCP is a purpose-built gateway with a narrow focus. Obot is an agent platform that happens to include a gateway. TrueFoundry is in the machine learning infrastructure space. Lunar.dev is trying to be a control plane for AI agents. Arcade is building agent-friendly tooling. The variety tells you that no one has won the architectural argument yet. Snowflake's advantage is distribution, not innovation. It has $1.33 billion in quarterly product revenue and existing relationships with most enterprise data teams. A startup cannot match that sales motion. But a startup can move faster. And Snowflake's gateway was assembled through acquisition, which raises the question of how deep the technical moat really is. The Natoma acquisition is a signal. It means Snowflake did not grow this capability in-house over a long horizon. It bought a team and a product. That is not a dismissal. Many of the strongest platforms in technology came from acquisitions. But acquired technology often comes with architectural debt and integration gaps. You can buy a toolkit, but you cannot buy the years of production scars that a mature platform would have accumulated. In an emerging protocol space, where best practices are still being written, the absence of scars is dangerous. Snowflake's bundling strategy is another unspoken threat to standalone vendors. The company could easily package Cortex AI Gateway into its existing data cloud subscriptions. That would put immense pricing pressure on independent gateways. If a customer is already paying Snowflake for the data cloud and the agent gateway, why buy a separate gateway from MintMCP? The counterargument is that standalone vendors can be more protocol-native and less biased toward Snowflake's data ecosystem. But in enterprise sales, convenience and budget consolidation usually beat technical elegance. The M&A tells us what matters. The Cyera-Oasis deal and the Okta-Permiso deal are not isolated events. They are a validation of the MCP gateway thesis. Cyera paid roughly $1 billion for Oasis, a security company focused on agent identity and MCP. Okta paid around $200 million for Permiso, a security startup that also understands MCP's identity implications. The fact that these deals closed within a 72-hour window suggests a coordinated market realization: if MCP is going to be the interoperability layer for agents, then MCP identity is the first security contract that enterprise customers must trust. Traditional identity vendors cannot build MCP-native features fast enough. The protocol is moving too quickly. The window for organic development is not years; it is months. Acquisitions are the only way to buy, rather than earn, that time. That is why Oasis and Permiso commanded premium prices. The assets are not just code. They are developer mindshare, existing integrations, and early customer proof points. The same dynamic is happening across the broader agent security market. Every security vendor is suddenly a gateway vendor. Every gateway vendor is suddenly an identity vendor. Every platform vendor is suddenly an audit vendor. The lines are blurring because the threat model has expanded. The agent can go anywhere. The gateway is the only place to check it. The attack surface is already open. NadMesh is not a theoretical research group. It is a botnet operation that has explicitly listed MCP as a first-priority attack surface. That sentence should scare everyone building agent infrastructure. Attackers do not advertise their favorite targets unless they have already found a reliable technique. NadMesh's behavior suggests the attacker community has already reverse-engineered MCP's weak points and has tooling ready to exploit them. What makes MCP so attractive to attackers? Three things. First, it is new. New protocols are rarely hardened. Second, it is connected. MCP servers are designed to reach enterprise data and external services. Third, it is trusted. Developers are more likely to wire an agent to an internal database than they are to give a random script the same access. MCP is the perfect bridge from a compromised foundation model to a sensitive backend. The 57% statistic compounds the problem. A recent data point says 57% of organizations report a significant security and risk management capability gap. That is not a MCP-specific measurement, but it explains why MCP adoption is so dangerous. Even if the gateway exists, most companies do not have enough skilled staff to configure it correctly, monitor its logs, and respond to a compromised agent session. A gateway without an operations team is just a false sense of security. In the MCP world, a false sense of security is worse than no security, because it increases the blast radius when someone eventually walks in. I have seen this before. During the DeFi summer aftermath, protocols with full audit reports were exploited because the audit was a static snapshot. The threat landscape moved after the audit was issued. The same will happen with MCP gateway configurations. The threat landscape will move faster than the policy updates. The first lawsuit signals legal maturity. Runlayer v. Rippling, filed in the Southern District of New York, is being described as the first major MCP-related intellectual property dispute. The precise claims matter less than the signal. MCP now has enough real-world commercial weight to trigger legal action. That changes the calculation for enterprise adopters. You can no longer evaluate an MCP server solely on technical security. You also need to evaluate whether its implementation infringes someone's patent or copyright. Legal risk is now part of the gateway risk model. Most security teams are not trained for that. Most procurement teams are. The lawsuit also hints at a broader issue: MCP's open standard is controlled by a single external actor, Anthropic, or at least heavily influenced by it. The companies building gateways on top of MCP do not control the protocol's governance. If the standard changes in a direction that favors one vendor, every other vendor must adapt. If a legal ruling restricts certain implementations, the entire ecosystem feels it. That is a structural vulnerability for Snowflake, Okta, and every partner at the table. Regulation didn't create this moment. Attack velocity did. The timing matters. Regulation, especially in the EU under MiCA and the broader AI Act conversations, is still catching up to deployment reality. No regulator told Snowflake to build a gateway. No law demanded that Okta buy Permiso. The market created the demand because the attack surface was expanding faster than the defense layer. The first company to offer a secure, enterprise-grade MCP gateway will have pricing power. The first company to suffer a public gateway breach will have scandal power. The difference will be measured in audit logs. Contrarian: The gateway is the new single point of failure. Here is the angle the press release does not want you to discuss. The rush to centralize MCP governance is also a rush to create the most concentrated target in enterprise AI. Before gateways, an attack on MCP infrastructure required targeting individual servers. You might compromise one CRM integration or one internal tool. With the gateway, one compromised token can authorize every tool call in an organization. That is not a theoretical risk. It is the history of identity providers. The industry spent the last decade moving from per-app passwords to single sign-on, and then spent the embarrassing years of hybrid cloud watching attackers exploit a single misconfigured SSO role to take over entire environments. We are about to repeat that exact cycle with AI agents. The six-word phrase identity, policy, and audit sounds noble. In practice, it means that the network perimeter has moved inside the agent's request handler. The gateway is not a shield; it is a rendezvous point. If an attacker can spoof an agent identity or steal a gateway session token, every downstream tool becomes accessible. The worst-case scenario is not a malicious MCP server. The worst-case scenario is an attacker with valid gateway credentials and no anomaly detection to catch the unusual tool-call sequence. That is why the identity partnerships are so important and so risky. With seven identity providers involved, the policy surface becomes enormous. Okta might say allow, but SailPoint might say deny, and Cyera might flag the action. What happens when policies conflict? Who is the final arbiter? Snowflake has not announced a clear arbitration mechanism. Based on my experience auditing access control systems, the most common security failure is not a missing control. It is ambiguous control. When policies overlap with conflicting permissions, administrators make patches, and patches create gaps. The same will happen in MCP gateways. The centralized gateway also creates an availability problem. If the gateway goes down, every connected agent loses access to every tool. That means the gateway's uptime becomes a business-critical metric. An enterprise with a $10 million data cloud contract will not tolerate a gateway outage during quarter-end reporting. The gateway vendor needs to build high-availability infrastructure across regions, with failover paths for every identity provider. That is not a simple engineering task. It is the kind of complexity that only emerges when you put a new chokepoint into a mature stack. There is also a protocol governance problem hiding in plain sight. MCP is an open standard driven by Anthropic. Snowflake, Okta, and the rest are building on top of a protocol they do not control. Anthropic can revise the spec, change licensing terms, or deprecate features. That is the structural vulnerability of every MCP gateway vendor. The deeper they integrate, the more dependent they become. It's like building a data center on leased land. The lease can be renewed, but the owner decides the terms. The centralization paradox is not limited to a single gateway. It applies to the cloud platforms. AWS Bedrock, Azure AI Foundry, and Google's agent ecosystem all have their own built-in gateway and orchestration layers. Snowflake is not fighting MintMCP. It is fighting the hyperscalers for the right to be the abstraction layer above their native services. A Snowflake gateway sitting on top of tools that are already inside Azure is an interesting architectural conversation. The outcome is likely to be a set of nested gateways, each adding latency and each creating another audit log that must be correlated. We didn't expect this to happen so quickly. But the market has decided: MCP gateway infrastructure is table stakes. The next question is whether the security architecture can evolve faster than the attack surface grows. History is not encouraging. The MCP statelessness effort is an admission that the previous session model did not scale. The NadMesh targeting is an admission that attackers are already one step ahead. And the Runlayer lawsuit is an admission that the legal system will be part of MCP's maturity arc. Takeaway: What to watch next. Snowflake has turned MCP into enterprise infrastructure. That is the headline. The subheadline is that infrastructure is never neutral. A gateway is a choke point. Choke points are either defended or captured. The enterprise security market is now engaged in the largest defensive land grab since the shift to cloud identity, and the attackers have already announced their presence. In the next six months, I will be watching three signals. First, wait for the Snowflake gateway's stateful handling. If the stateless MCP spec is not compatible with the gateway's audit continuity, every enterprise deployment will be a workaround. The protocol revisions that follow will tell you which layer has power. Second, watch the policy arbitration layer. The seven identity partners are a coalition, but coalitions have internal conflicts. The first time a customer tries to enforce a global deny rule across all seven identity sources, you will see whether the gateway is a real governance platform or just a sales deck. Third, watch the incident reports. NadMesh is not the last threat actor to target MCP. The first publicly disclosed gateway compromise will not be a jailbreak. It will be a stolen session token that allowed a legitimate tool call to do something illegitimate. When that happens, the security industry will call it an advanced persistent threat. The rest of us will call it a failure of the centralized architecture we just embraced. Regulation didn't make MCP gateways compulsory. Fear did. We didn't see a future where enterprise AI security depends on a few gateways. We are about to live in it.

Snowflake Just Turned MCP Into Enterprise Infrastructure. The Attackers Already Knew.

Snowflake Just Turned MCP Into Enterprise Infrastructure. The Attackers Already Knew.