'Whisper attacks' steer Google AP2 shopping agents into validly signed wrong carts with 56-90% success across 17 Google models
arXiv 2609.11757 shows that the Agent Payments Protocol signs completed transactions but not the decisions behind them, so product-description text can steer the agent. Against the Gemini Flash-Lite models AP2's sample agents use by default, the attacks fetched another user's payment credentials 90% of the time, built a mismatched but valid cart 56% of the time, and upsold to a pricier item from a single stock claim 73.3% of the time. The weakness reproduced across seventeen Google models, three other frameworks and Google's consumer assistant. The authors release A-VIP, which binds each credential lookup to its session and each cart line to the listing the user saw, along with AP2-WhisperBench (1,544 scenarios).
Source
↳ Follow the thread