Skip to content
Preprint

Signing the Transaction but Not the Decision: Whisper Attacks and a Binding Defense for AP2

Sep 2026 · 0 citations · 70 references
Computer Science

TL;DR

A-VIP (AP2 Verified-Intent Protection), a protocol-layer defense that treats the signed intent as a capability grant rather than judging the merchant's description, is introduced, to address this attack vector.

Abstract

Software agents are beginning to shop and pay on a person's behalf. Agent payment protocols such as AP2 produce cryptographically valid signatures for completed purchases, yet do not constrain the decisions that lead to them. Consequently, ordinary product-description text can steer a shopping agent into forming a cart that passes every protocol check but no longer matches the user's request. In this paper, we show that this vulnerability enables three related attacks. In the first attack, the agent is steered into fetching another user's payment credentials. In the second, it assembles a cryptographically valid cart whose contents do not match what the user was shown. In the third, a single factual claim about stock or product lineage moves the agent from the cheaper displayed item to a more expensive one, while the resulting cart remains fully consistent with the listing. In experiments using the Gemini Flash-Lite models that AP2's sample agents specify by default, the three attacks succeeded at rates of 90%, 56%, and 73.3%, respectively. The same vulnerability appears across seventeen Google models, three unrelated agent frameworks, two cross-vendor anchors, and Google's own consumer assistant. To address this attack vector, we introduce A-VIP (AP2 Verified-Intent Protection), a protocol-layer defense that treats the signed intent as a capability grant rather than judging the merchant's description. The defense binds every credential lookup to the session that requested it and every cart line to the listing seen, while flagging unauthorized spending. The first two attacks leave structural traces that these bindings block with zero false positives. The third attack leaves no trace, so A-VIP surfaces unauthorized spending for user confirmation. Finally, we release the A-VIP code, machine-checked invariants, and AP2-WhisperBench, a suite of 1,544 evaluation scenarios.

View source

Similar papers

#artificial intelligence Preprint Sep 2026

Issuer-Sovereign Agentic Payments

AI agents are beginning to make real payments. Current approaches let an agent pay by relying on a credential provider that, in the approaches deployed today, typically sits outside the cardholder's bank. The spending rules are then enforced by the card network or that provider, and not by the bank itself. This leaves...

Disha Sharma, R. Kaushal, Ashu Kanaujia · 0 citations
Preprint Aug 2026

Separating Disclosure from Authorization: Field-Tier Minimization for Agent Action Mediation

A system that authorizes an action must see enough of it to decide, and a system that attests to its decision must record enough to be audited. Both pressures push raw action parameters -- recipients, payment memos, record identifiers -- into an append-only ledger that cannot delete them. We show the two are separable....

Jiten Oswal, John Cadeddu · 1 citation
#artificial intelligence Review Sep 2026

Agentic Commerce Bench: Measuring Fraud Detection for Agents That Spend Money

AI agents now hold spend authority and settle payments without per-action human confirmation. The resulting loss is often not a security failure: a counterparty with the correct domain, the correct settlement address and a genuinely delivered service can charge more than it should, and no check keyed on identity will s...

Ankit Srivastava, Debjyoti Paul · 0 citations
#artificial intelligence Preprint Aug 2026

A Formal Analysis of Agent Payment Protocols

This work formalizes four representative agent payment protocols: x402, MPP, ACP, and AP2 in Tamarin, and constructs source-grounded models that capture each protocol's roles, state, trust assumptions, and lifecycle transitions.

Ke Jiang, Mo-Han Yu, Yuan-Yi-Chun-Min-Chieh Chang et al. · 0 citations
#artificial intelligence Preprint Sep 2026

terms.txt: A Consent and Compensation Protocol for Agentic Web Access

The open web ran on an unwritten bargain: sites admitted crawlers, and search engines sent visitors back. Public measurements show that bargain breaking under AI crawlers and agents. Automated clients now make up most requests, training dominates Cloudflare-classified crawling, and the largest AI platforms fetch thousa...

R. Chowdhury · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.