Research · curated 30 Jul 2026

Protocol-Level Attacks on Agentic Commerce Platforms: A Cross-Platform Taxonomy, AIP-Bench, and Unified Defense

Coverage timeline

30 Jul 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

Agentic commerce platforms already move real money, and this work shows exploitation lives in the agent-to-service protocol layer where no model alignment improvement removes the flaws, meaning defenders must harden the protocol itself rather than relying on the LLM.

A research paper by Yedidel Louck (Ariel University) titled "Protocol-Level Attacks on Agentic Commerce Platforms" identifies 33 structural vulnerabilities across three production agentic commerce platforms, each exploitable deterministically at 100% attack-success rate regardless of the underlying model, including three that chain into an end-to-end payment hijack (e.g. a marketplace service description injecting a malicious settlement address). The authors contribute a taxonomy separating structural from model-dependent semantic attacks, AIP-Bench (a deterministic agentic-commerce security benchmark), and PCAT, a platform-agnostic defense that drives the structural attack-success rate to zero for four of five structural classes.