Research · curated 30 Jul 2026
Protocol-Level Attacks on Agentic Commerce Platforms: A Cross-Platform Taxonomy, AIP-Bench, and Unified Defense
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Agentic commerce platforms already move real money, and this work shows exploitation lives in the agent-to-service protocol layer where no model alignment improvement removes the flaws, meaning defenders must harden the protocol itself rather than relying on the LLM.
A research paper by Yedidel Louck (Ariel University) titled "Protocol-Level Attacks on Agentic Commerce Platforms" identifies 33 structural vulnerabilities across three production agentic commerce platforms, each exploitable deterministically at 100% attack-success rate regardless of the underlying model, including three that chain into an end-to-end payment hijack (e.g. a marketplace service description injecting a malicious settlement address). The authors contribute a taxonomy separating structural from model-dependent semantic attacks, AIP-Bench (a deterministic agentic-commerce security benchmark), and PCAT, a platform-agnostic defense that drives the structural attack-success rate to zero for four of five structural classes.