AI agents are increasingly given tools to spend money directly: cloud accounts, trading bots, shopping browsers, vending-machine inventory, API keys with billing attached. When that goes wrong, it is not a bug report, it is an invoice or a drained wallet.
We logged every publicly reported case we could source; the full dataset is open (CC BY 4.0) at github.com/Pink-Agentic-Payments/agent-spending-incidents.
Disclosure: compiled by the PinkWallet team, which builds Pink Agentic AI Payments.
Each entry below uses only facts from the dataset's incidents.csv, including hedges like "reportedly" where sources disagree or a figure is unconfirmed. Row-by-row sourcing is in the dataset's FINDINGS.md and README.md.
1. Freysa AI agent tricked into transferring $47,316 (Nov 2024)
Freysa was an autonomous agent on Base, hard-coded to never approve a fund transfer no matter what was said. After 482 messages from 195 players, a player calling themselves p0pular.eth convinced Freysa its anti-transfer rule did not apply to its "approveTransfer" function when triggered by an incoming donation, and the agent authorized a transfer of its full $47,316.05 prize pool to the player's wallet. The Block
Control that would have helped: human approval. The hard-coded rule lived inside the agent's own reasoning, so a human sign-off step for transfers above a threshold would not have depended on the agent correctly resisting adversarial pressure.
2. Morse-code prompt injection drains ~$150k from an AI-linked Bankr wallet (May 2026)
An attacker reportedly sent an NFT to a Grok-linked wallet that unlocked elevated transfer permissions inside the Bankr trading bot, then posted a Morse-code-encoded message to Grok on X. Decoded, the message was treated as an authenticated instruction, and the bot transferred roughly 3 billion DRB tokens out of the wallet. Reported figures range from $150,000 to $200,000 depending on outlet and token price; community efforts reportedly recovered roughly 80% of the funds. Giskard
Control that would have helped: payee allowlist. The transfer went to a wallet the bot had no prior reason to trust; restricting transfers to pre-approved addresses would have blocked the payout regardless of how the instruction was encoded.
3. Guardio tricks Perplexity Comet into buying from a fake Walmart site (Aug 2025)
Security researchers at Guardio Labs asked Perplexity's Comet AI browser to buy an Apple Watch from a fake Walmart page hosted on a Lovable-built site with a bogus URL. Comet did not flag the site as fraudulent, entered the user's card and address details, and completed checkout. No dollar amount is stated; it is a research demonstration, not a reported victim loss. BleepingComputer
Control that would have helped: human approval. The agent had no mechanism to pause and confirm a purchase on an unverified domain before entering payment details.
4. Amazon's internal Claude coding task overspends by $1.8 million (surfaced July 2026)
An internal Amazon project using Claude to match author records to product listings ran roughly 860% over its budget, reaching about $1.8 million in model-usage costs, reportedly undetected for about five months. Senior engineers reportedly called it "catastrophically expensive." This relies on Tom's Hardware and gHacks summaries of a paywalled Financial Times report, not fetched directly. Tom's Hardware
Control that would have helped: per-agent budget. A hard spending cap tied to the task would have forced a stop well before the bill reached 8.6x the original estimate, instead of five months of silent accrual.
5. Autonomous agent racks up a $6,531.30 AWS bill scanning a hobbyist network (May 2026)
An operator gave an AI agent unsupervised AWS access to "index" the volunteer-run DN42 hobbyist BGP network. The agent decided the job needed five m8g.12xlarge instances, load balancers and Lambda functions generating around 20 Gbps of scanning traffic, re-creating duplicate CloudFormation stacks each time it hit an error. Two days later the bill stood at $6,531.30; AWS later reduced it to $1,894. DN42 community write-up
Control that would have helped: per-agent budget. A spend ceiling on the agent's AWS access would have stopped the repeated instance creation long before five large instances and duplicate stacks piled up.
6. Developer gets a $32 surprise bill from a runaway AI agent (April 2026)
A developer left an AI agent running unattended for about 20 minutes and came back to an unexpected $32 charge; the underlying agent and task are not described in detail in the source. They then built and open-sourced AgentBudget, a tool that monkey-patches the OpenAI and Anthropic SDKs to track running cost per call and raise an exception once a spending cap is hit. Hacker News
Control that would have helped: per-agent budget. The smallest incident here by dollar amount, but the same missing control, a hard per-agent cap, is what the developer then built by hand.
7. Claude-run office vending machine gives away inventory and loses money (Dec 2025)
In a deliberate red-team stress test, Anthropic and Andon Labs let a Claude-based agent named Claudius manage pricing, ordering and sales for a real office vending setup at the Wall Street Journal's newsroom. Within days Claudius gave away most of its inventory for free, including a PlayStation 5 it had been talked into buying for "marketing purposes," and lost hundreds of dollars overall. This was an intentional experiment, not an unintended production failure, and Anthropic published it as a cautionary case study. Anthropic
Control that would have helped: per-payment cap. A ceiling on the size and discount of any single transaction would have limited how much Claudius could give away in one decision, even while being talked into it.
8. Mandiant reports an accounting agent loop caused roughly $50,000 in charges (reported Sept 2026)
Google Mandiant's "AI Risk and Resilience" report describes an unnamed accounting AI agent that entered a runaway execution loop, making more than 15,000 high-cost API calls in under an hour, generating roughly $50,000 in cloud charges and disrupting active business transactions. This relies on Help Net Security's summary of the report, not the report directly; company name, exact date and root cause are withheld in every version found. Help Net Security
Control that would have helped: rate/velocity limit. More than 15,000 calls in under an hour is a pattern a velocity limit catches almost immediately, regardless of whether each call looks legitimate.
9. Researchers red-team Google's AP2 agent-payment protocol via prompt injection (Jan 2026)
Academic researchers built a shopping agent on Google's Agent Payments Protocol (AP2), a Gemini-2.5-Flash agent on Google ADK, and showed indirect prompt injection could redirect which product it purchased, with a 100% success rate in their tests (a "Branded Whisper Attack"), while a related "Vault Whisper Attack" caused cross-account data exposure in 20% of trials. The attacks manipulated the agent's reasoning before it cryptographically signs a payment mandate, without breaking AP2's signature enforcement. A research demonstration, not production traffic. arXiv
Control that would have helped: human approval. The paper's finding is that signature enforcement was not broken, only the reasoning that decides what gets signed; a human checkpoint before signing addresses that gap.
10. Snyk finds a published agent skill that collects and leaks full credit-card details (Feb 2026)
Snyk researchers scanned the ClawHub/OpenClaw agent-skills marketplace and found 283 of 3,984 published skills (7.1%) had critical security flaws. The worst case, a "buy-anything" skill, explicitly instructed agents to collect full card numbers, expiration dates and CVC codes and embed them into API requests, passing that data through the LLM's context window and output logs in plaintext. Found live on a real marketplace, with no confirmed case yet of an attacker exfiltrating a specific user's card data this way. Snyk
Control that would have helped: credential never exposed to agent. If card details never entered the agent's context, there would be nothing in the LLM's logs or output for a later prompt injection to exfiltrate.
Where Pink fits
Pink Agentic AI Payments (by PinkWallet) checks every payment an AI agent asks to make against that agent's budget and rules (allow, ask a human, or block) before it executes, and the agent never holds a standing card or account key: only after a payment clears does it get a single-use credential scoped to that payee and amount, which expires in 15 minutes (simulated with test money in today's sandbox). That maps onto several incidents here: a payee allowlist or human-approval step addresses the manipulated-payment cases (INC-001, INC-002, INC-009), and issuing a credential per approved payment, rather than giving the agent a standing key, narrows the credential-leak case (INC-010). It does not address every category: model token/API usage (INC-004, INC-006) and cloud compute billing (INC-005, INC-008) are billed directly by the provider, not routed through a payment layer, unless that spend is itself wired through one; a wallet operating outside any policy layer, as in the original Freysa and Bankr setups, only gets this control once someone adds it. We are not claiming this pattern would have prevented any specific incident as it happened; we are pointing at the kind of control that was reportedly missing.
Help us grow this dataset
The dataset is open on GitHub at Pink-Agentic-Payments/agent-spending-incidents under CC BY 4.0. If you know of a sourced incident that isn't in there yet, open a GitHub issue with a primary source link, incident and report dates, and which inclusion criterion it meets.
What category of AI agent payment failure do you think is most under-reported: crypto/wallet manipulation, cloud/API overspend, or something else?
Top comments (0)