Fetching from the wire…
Public story · 2026-09-11 · high
Researchers steered Gemini-based AP2 shopping agents into fetching another user's payment credentials 90% of the time.
Why now: The paper posted to arXiv in September 2026, while AP2's sample agents still default to the vulnerable Gemini Flash-Lite models.
Hidden text in a product description steers Google's Agent Payments Protocol into building the wrong cart, per a paper testing AP2.
The protocol's signature confirms an agent finished a purchase, not that it read the right listing to get there. For the shopper, that gap means an agent can authorize real money against a cart they never approved.
The researchers call it a whisper attack. The steering text sits inside the product listing itself. Against the Gemini Flash-Lite models that power AP2's sample agents by default, the attacks fetched another user's payment credentials 90% of the time. They also built a valid, signed cart that didn't match what the buyer saw 56% of the time. Both attacks worked through ordinary listing text. AP2's cryptography wasn't broken.
The weakness reproduced across 17 Google models. It also reproduced across three other agent frameworks.
The paper's authors released a fix, A-VIP, which ties each line in a cart back to the specific listing the shopper viewed.
Each link below shares sources, entities, or timing with this story.
Google launched agentic video understanding across Gemini 3.7 Flash, 3.6 Flash and 3.5 Flash-Lite (Google). Instead of scanning a video start to finish at a fixed sample rate, the model runs an internal loop deciding what to watch, at what speed, and through which channel: fra...
Forerunner led a $30M Series A into Natural on July 20 to build "the transactional plumbing required for AI agents," entering a field that already has Google's UCP, OpenAI's ACP, Stripe/Tempo's MPP (with Visa as design partner), Google's AP2, Ant International's AMP, and Maste...
arXiv 2609.09553 shows cipher-based covert-communication jailbreaks no longer need fine-tuning on an encrypted corpus. In-context learning is enough, and alignment is significantly weakened or bypassed once the exchange runs through the learned encoding. Demonstrated against m...
Testing the human influence technique on nine production models from three providers produced a split by family. Opus 5 answered the smaller request 65.8% of the time after refusing a larger version, against 29.3% asked directly. On OpenAI's and Google's frontier models and on...
Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber, the last purpose-built to find and patch vulnerabilities and pitched as a cheap alternative to large security-specialized models like Mythos (DeepMind). Splitting a cheap tier into a security SKU is new packa...
Per SSOJet, that cross-company contributor base is the unusual part. OSS coding agents usually orbit one vendor. This one's becoming shared infrastructure, which makes it the self-hostable default to watch against proprietary agents. If you want a coding agent you can run and...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.