Tech
AI’s most important protocol is getting a little bit easier to use
The Model Context Protocol (MCP) is one of the basic building blocks of AI interoperability, giving AI models a secure way to access external data sources and services. It’s the plumbing that lets a chatbot reach into your calendar, your database, or your internal tools, instead of engineers building custom pipes for every connection. Next week, that protocol is getting a significant update, and while it might not be noticeable to end users, it could make a big difference in how the ecosystem develops.
The official spec for the new version has been public since May, but we got an unusually clear explanation of the changes Monday morning from the folks at Arcade — a two-year-old startup that’s built its entire business around the work of getting AI agents to actually function inside real companies, letting them securely connect to and act on tools like Gmail, Slack, and Salesforce.
Arcade raised $60 million in June based on the idea that most AI agents don’t fail because the underlying models are weak but because the infrastructure around them isn’t ready yet, and that’s what this update is trying to address. Essentially, MCP is changing the way it handles session IDs — the little tokens that servers use to remember “ah, this is the same conversation as five seconds ago” — so servers can operate more easily at a larger scale.
As Arcade founder Nate Barbettini puts it:
[Under the current system] The first time an MCP client like Claude connects to a server, it sends a “hello”: I’m Claude, here’s my version, here are my capabilities. The server replies with its own capabilities and hands back a session ID… From then on, the client sends that session ID on every request so the server knows it’s the same conversation. Sometimes the ID expires, so the client has to notice, request a new one, and carry on….
Picture a real deployment. You’re running a server for millions of users, behind a load balancer whose entire job is to route each request to whatever server in the farm is free, sometimes in a different region. Now every one of those machines has to know about a session ID that some other machine handed out. It’s not impossible, but it’s a serious pain, and it fights the load balancer instead of working with it.
In other words, the current setup assumes one server remembers you, but real companies spread traffic across dozens of servers that don’t talk to each other by default, so today’s MCP servers have to do extra work just to keep track of who’s who. That’s been a significant headache for anyone running an MCP server at scale, and part of the reason we haven’t seen more companies ship large-scale, first-party MCP integrations despite all the hype around agentic AI this year.
Under the new system, the protocol will take a looser, “stateless” approach to session IDs on the server side, similar to how most ordinary websites already work, which should make the whole system a lot easier to maintain and, in theory, cheaper to run at scale.
That’s all pretty technical, but it’s an important reminder that not every part of AI development is moving at breakneck speeds. While model training races ahead, a lot of the technical infrastructure those models need is still subject to the slow log-rolling of standards-body consensus. It really is happening; it’s just a little slower!
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Passionfroot raises $15M to expand its B2B creator marketplace to the US
Passionfroot, a German startup building a marketplace connecting B2B creators with brands, said on Wednesday it has raised $15 million in a Series A funding round led by Insight Partners.
Rebecca Liu-Doyle, managing director at Insight Partners, said Passionfroot is placed well at a time when creators are specializing as AI companies look for more visibility.
“Passionfroot has the perfect dynamics on both sides to warrant a true marketplace for B2B creators. On the demand side, there is increasing consumerization of the way B2B brands go to market. That’s a product of, in part, AI technology requiring evangelism, narrative building, and education. On the supply side, there are people who have real expertise, understand a market deeply, and want to create quality content,” she told TechCrunch over a call.
With the funding, the Berlin-based startup’s co-founder and CEO, Jen Phan, is moving to New York, where Passionfroot is opening an office to expand its U.S. operations. The company is also opening an office in São Paulo, and expanding its current headcount of 15 employees.
As AI makes it easier to build products, companies are focusing on using creators to improve brand recall and recognition, Phan said.
“Every head of marketing or growth leader I’m talking to is saying really the same thing: AI is commoditizing software and flooding every category with new products, features, and launches. It’s incredibly crowded and noisy. That is why B2B buyers are going to channels like LinkedIn, a creator’s Substack, or a podcast on YouTube to discover new products and tools,” she said.
Phan said over the last year, the company increased its revenue by 13 times, and onboarded clients such as ElevenLabs, Figma, Replit, Framer, and Gamma.
Since its last fundraise in 2024, the company has released an AI agent called Zest, which helps brands create, execute and monitor the performance of campaigns. Passionfruit claims Zest can also help companies find suitable creators both inside and outside the platform that are suited to its marketing strategy.
The startup says it uses a proprietary creator graph based on data about reach and performance from thousands of campaigns. There’s also a wallet that companies can use to pay creators across the globe, and measure their expenditure.
Passionfroot claims it has paid at least $10 million to creators on its platform in the last 18 months.
The company says it is working on helping its clients measure how a campaign is impacting AI citations, and how their brand appears in AI-powered answers. The startup is also planning to build AI features for creators, such as helping them with monetization tips and content ideas.
The funding comes as creator platforms like Substack and Beehiiv move to help creators find better monetization opportunities. Beehiiv launched a new community and ad marketplace last week, and Substack has introduced subscriber-only perks within newsletters.
Passionfroot’s Series A also saw participation from existing investors Creandum, Supernode Global, and s16vc. The company has raised more than $21 million so far.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Cascade raises $3.5M to help construction firms find and win projects
Cascade, a startup building a platform to help architecture, engineering, and construction firms find and win projects, has raised a $3.5 million seed round from Andreessen Horowitz Speedrun, Ada Ventures, and Snowball VC.
Launched in 2025, Cascade is a result of its founders, Hannia Zia and Joana Ferreira, witnessing firsthand the difficulty construction businesses face with predictably securing work.
“My mother worked in a company that sold materials to construction companies, and my uncle built mansions in the Middle East. They’re incredible at their craft but just don’t have access to the right tools to get more work,” Ferreira told TechCrunch. And Zia recalled the time her father tried starting a construction business back in her native Pakistan: “He just couldn’t get enough projects to sustain himself.”
Zia describes the current process of finding construction projects as a “constant treasure hunt,” with firms having to log into each U.S. state, city, district, county, and federal agency’s portals. “So if you’re really good at building suspension bridges, you have to find all of those opportunities across these disparate portals.”
Cascade aims to help architecture, construction, and engineering firms on this front by tracking ongoing and upcoming projects, and then using prior tender data to predict which developers are likely to win the deals.
Here’s how the platform works: A company signs up to the platform, and then Cascade uses AI tools to determine which projects they have the best chance of winning. It also predicts what projects are coming up, using different signals and data points across U.S. states, local districts, private contracts, and federal agencies. For example, if a state announces a $100 million affordable housing grant, Cascade will monitor which developers won the grant the last time it was announced.
“We connect that data, and we tell our customers: ‘Most likely one of these five developers will win this newly announced grant, so go start talking to them to win projects,’” Ferreira explained.
The duo applied to a16z’s Speedrun last September. They said the pressure to do well on demo day and being around the “brilliance” of other founders helped the company sign contracts with firms that have built the JFK and La Guardia airports, Four Seasons hotels, and some data centers. “Speedrun gave us visibility and a stamp of approval to close big deals,” Zia said.
The startup will use the fresh cash to go to market, host industry events, and hire more engineers.
Other startups in this area include GovWin IQ and ConstructConnect, but Ferreira argues Cascade is a bit more AI-native than these platforms.
“Every time a customer wins a bid, they give feedback, so the system keeps getting smarter. Over time, we’ll have a complete map of the industry that our AI can traverse to predict the best projects and leads for each customer,” she said.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
If you pay a hacker’s ransom, chances are that they’ll come back for more
Governments have long warned not to pay a hacker’s ransom demands, arguing that doing so only lets criminals profit from their cyberattacks and funds the next one. There’s also another reason: The hackers are unlikely to leave you alone if you pay up once, and many will come back demanding more.
In a report published Wednesday, cybersecurity giant Proofpoint said it surveyed 953 companies and found that over one-third of companies that paid a hacker’s ransom were hit with a second extortion demand. The findings underscore the long-held understanding among security researchers and network defenders that it’s impossible to negotiate in good faith with an extortion racket because there’s no incentive for the other side to actually walk away.
Proofpoint’s data shows that ransomware attacks and extortion attacks have evolved from a single transaction where hackers would get paid once and move on, into an effort using multiple forms of leverage, such as retaining stolen data under the threat of publicly releasing it.
While hackers have claimed in the past that they will delete or destroy the victim’s stolen data, past incidents have shown that not to be the case.
Last month, a hack at market research firm Klue exposed data belonging to its customers, including several cybersecurity firms. The company said it struck a deal with the hackers, who claimed to have deleted the data, but the company later conceded that a separate hacking group swiped a sample of the company’s stolen data, leaving its customers exposed to potential future extortion demands.
A similar situation befell Change Healthcare in 2024, after a Russian-speaking ransomware gang stole the health and medical data of the majority of people in America, some 192 million people. Amid a dispute between the hackers and their affiliates (criminal groups often subcontract out attacks), Change Healthcare paid separate ransoms to both groups of criminals to keep the sensitive medical data off of the internet.
Security researchers have long suspected that ransomware gangs and extortion rackets will keep hold of the victim’s stolen data, even after a payment is made. U.K. law enforcement confirmed this during their takedown efforts targeting the prolific LockBit ransomware gang in 2024. Police said that they found victims’ stolen data stored on LockBit’s servers long after they had paid the ransom.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
