Research · curated 30 Sep 2026
Persistent Billable State: Denial-of-Wallet Attacks and Defenses in Tool-Calling LLM Agents
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Denial-of-wallet via persistent billable state gives an admitted malicious tool a way to inflate a victim's LLM-agent costs without credentials, and the study finds only 71 of 3,830 scanned MCP server/transport repositories expose any safeguard proxy.
The paper 'Persistent Billable State' presents the first systematic study of denial-of-wallet attacks against multi-step tool-calling LLM agents, where a malicious or compromised tool converts untrusted data retained across turns into recurring victim-billed processing. The authors derive six attack vectors, build the DOW-BENCH harness across six model families (measuring cumulative input reaching up to 14,293x the first-call input), and propose host-side invariants that bound prompt mass, context growth, recursion, and cumulative spend before reingestion.