Fetching from the wire…
Public story · 2026-08-26 · high
A new analysis of AP2 v0.2 found eight high-severity gaps where signed payment mandates don't cover the steps that set up the transaction.
Why now: The analysis posted to arXiv on August 24 and covers the deployment architectures teams are building against now.
Google's Agent Payments Protocol lets AI agents complete purchases with a signed Payment Mandate standing in for the user's authorization. A new analysis of AP2 v0.2 finds that signature covers less than it looks like it does.
The paper models AP2 across five lifecycle phases and five deployment architectures using the MAESTRO threat framework, and catalogs 48 distinct threats scored with AIVSS. Eight land in the High severity band in at least one architecture.
The structural problem is where the protection starts. AP2's signed Checkout and Payment Mandates lock in transaction data once they're signed. But the A2A messages and MCP tool calls that build that transaction beforehand, the steps where an agent decides what to buy and for how much, sit outside the signature entirely. A valid signature proves someone signed off on a mandate. It doesn't prove the mandate reflects what the user actually asked for, because nothing upstream of the signing step is protected.
The authors didn't just theorize the gap. They built a testbed spanning all five architectures and five proof-of-concept demos, one for each High-severity threat, plus a scanner that checks deployments against static, cross-role consistency, and adversarial tests.
For anyone wiring agents into a payment flow, the lesson is specific: the signature check on a mandate tells you it wasn't tampered with after signing. It tells you nothing about whether the pre-authorization conversation was manipulated. Teams building on AP2 or protocols like it need to validate the request-shaping steps, not just the final signed artifact, and the paper's scanner is a starting point for what that validation should look like.
Each link below shares sources, entities, or timing with this story.
An attacker stole an AI agent's signing keys through email injection in under five minutes, per a prior incident this design cites.
Escaped quotes and curly dollar signs planted in sender-name fields fooled six frontier models, beating purpose-built defenses half the time.
OpenAI Devs announced on August 26 that WebMCP works in the ChatGPT desktop app's built-in browser and in ChatGPT Sites, so ChatGPT and Codex can call a site's declared tools directly. WebMCP is an experimental web standard adding navigator.modelContext to the browser, letting...
Planted skills captured the model's coordinator in 80% of test cases while runtime nearly doubled and task completion stayed unchanged.
ActBench ran 24,000 attack trajectories across 15 models and six harnesses; no harness pushed success below 73.7%.
It automates the data-flow, crash-semantics, and commit-history work engineers do by hand.
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.