Updated 2026-09-25. Next update 2026-12. Quarterly. Only verified, sourced items. Research findings are not reported as production losses.
Entries
2026-07-02 · AI-agent incident research
Hidden page instructions and agent payments (Zscaler ThreatLabz)
ThreatLabz described fraudulent sites that hide instructions telling a browsing agent to pay for a fake API license. In their sandbox, 4 of 26 models executed the payment. They also described a typosquat that some models treated as a known crypto site. Testing used a sandbox. The report does not establish a victim-loss total for the campaign.
Loss. Not established. The payment framed in the test was about $3, described as about 0.0012 ETH.
Cause. The agent treated untrusted page content as an instruction to pay.
Control. Intent mismatch against the original task, plus a block on payees that are not allowlisted.
Zscaler ThreatLabz, 2 July 20262026 · Protocol research — not a reported production loss
Five attacks on the x402 payment protocol (published research)
The authors analyze x402 and report five attack classes against authorization, binding, replay protection, and web-layer handling. They describe a testbed of more than 25,000 payment requests. This index does not repeat exploit steps.
Loss. Not a reported production-loss figure.
Cause. Payment authorization was not bound tightly enough to the resource and the settlement.
Control. Bind each payment to the resource and the intent, and refuse replayed or substituted authorizations before settlement.
arXiv:2605.117812026 · Protocol research — not a reported production loss
Free-riding analysis of x402 payments (published research)
The authors report four flaw classes, including cross-resource substitution, duplicate-settlement races, allowance overdraft, and denial of settlement, against official SDKs and a production deployment in their tests. They state findings were disclosed.
Loss. Not a reported production-loss total. Their tests report resource-leakage ratios, which are not customer-loss statistics.
Cause. Spending allowance and settlement state could diverge.
Control. Hard spending limits re-checked at settlement time, with one-time authorization.
arXiv:2605.309982026 · Protocol research — not a reported production loss
Facilitator rule review of live x402 deployments (published research)
The authors say they tested 15 x402 facilitators and found rule violations in all of them, then disclosed the issues. They write that affected parties acknowledged issues and that mitigations included changes by Coinbase. They do not publish a dollar loss for a named incident.
Loss. No incident dollar total in the paper.
Cause. Shared facilitator checks did not enforce the authors' settlement and authorization rules.
Control. A policy check before the agent pays, independent of the facilitator.
arXiv:2607.195452022-07-01/2024-06-30 · Automated fraud measurement — not an AI-agent incident
Address-poisoning measurement on Ethereum and BSC
Tsuchiya, Dong, Soska, and Christin measure poisoning transfers that plant lookalike addresses in transaction history. Across Ethereum and BSC through 30 June 2024 they report 6,633 successful incidents and at least $83.8 million in losses. They note the estimate is a lower bound and that a well-known wrapped-bitcoin case is not inside this dollar figure.
Loss. At least $83.8 million across 6,633 incidents.
Cause. A payment went to a lookalike address taken from recent history.
Control. Block or hold the first payment to an address that is not allowlisted, and require counterparty verification.
USENIX Security 2025, Tsuchiya, Dong, Soska, and Christin2024-05-03 · Address poisoning — not an AI-agent incident
Wrapped-bitcoin address poisoning
Chainalysis describes an address-poisoning scam on 3 May 2024 in which a large holder sent about $68 million in wrapped bitcoin to a lookalike address. Chainalysis reports the attacker returned that position on 9 May 2024 and that the scam still netted about $1.49 million after the return.
Loss. About $68 million sent, later returned. About $1.49 million reported as still retained after the return.
Cause. The sender used a lookalike address from poisoned history.
Control. New-address block and out-of-band verification before a large first payment.
Chainalysis, Anatomy of an Address Poisoning Scam2012-08-01 · Automated system — not an AI-agent incident
Knight Capital automated order router
On 1 August 2012 Knight's automated router sent a flood of erroneous equity orders. The company's 2 August 2012 release said the firm had traded out of the position at a realized pre-tax loss of about $440 million. The SEC's 2013 order states Knight lost more than $460 million after the router, processing 212 customer orders, obtained millions of executions in about 45 minutes.
Loss. About $440 million in the company release. More than $460 million in the SEC order.
Cause. A defective automated path kept sending orders after the intended quantity was filled. Limits did not stop it.
Control. A hard quantity and notional limit that blocks further orders, plus an audit alert a human must clear before the session continues.
SEC press release 2013-222; company release filed as SEC exhibit, 2 August 2012