← Back to DEF CON 34 posters

Presented at DEF CON 34

Poisoned Mandates: Stealing Agency from Agentic Commerce

  • Saish BhorpeRepello AI
  • Aryan BhujangRepello AI
  • Aryaman BeheraRepello AI

Abstract

Three protocols launched in late 2025 to let AI agents shop and pay for you: Google's Agent Payments Protocol (AP2), Stripe and OpenAI's Agentic Commerce Protocol, and Visa's Trusted Agent Protocol. All three sign mandates, scope tokens, and separate roles. None of them treat the merchant's product description as input an attacker controls.

We put text in one product-description field and walked it through AP2's reference implementation end to end. A registered merchant with an ordinary storefront is all it takes. We built five escalating attacks, each breaking a different part of the pipeline. The agent presented the wrong product. It then overrode a user who said no seven times. It carried the payload across the whole agent chain and cleared eight human-in-the-loop checkpoints, including the one-time-password step. It defamed a competitor's product with invented reviews. Finally, one poisoned listing corrupted a separate, unrelated purchase the user made later. Every attack produced a cryptographically valid, signed payment mandate for a transaction the user never approved.