Research · curated 30 Sep 2026

Persistent Billable State: Denial-of-Wallet Attacks and Defenses in Tool-Calling LLM Agents

Coverage timeline

30 Sep 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

Denial-of-wallet via persistent billable state gives an admitted malicious tool a way to inflate a victim's LLM-agent costs without credentials, and the study finds only 71 of 3,830 scanned MCP server/transport repositories expose any safeguard proxy.

The paper 'Persistent Billable State' presents the first systematic study of denial-of-wallet attacks against multi-step tool-calling LLM agents, where a malicious or compromised tool converts untrusted data retained across turns into recurring victim-billed processing. The authors derive six attack vectors, build the DOW-BENCH harness across six model families (measuring cumulative input reaching up to 14,293x the first-call input), and propose host-side invariants that bound prompt mass, context growth, recursion, and cumulative spend before reingestion.