Research
Denial-of-Wallet: A Malicious Tool Return Re-Billed Every Turn Pushed Cumulative Session Input to 14,293x the First Call
arXiv 2609.28585 names 'persistent billable state': a tool output that the host runtime carries into later turns, where the provider meters it again. Across 243 executions on six model families, DOW-BENCH saw per-session cumulative input reach 14,293x the first call's input, and keeping raw history raised mean session cost 21.2-35.9%. The defense is host-side: deterministic history compression (10-11 of 12 history-dependent tasks succeeded, against 2 of 12 under deletion) plus four invariants that bound prompt mass, context growth, recursion and cumulative spend. Together these contained every recurring attack in a 123-run replay corpus.
Source
↳ Follow the thread