Denial-of-Wallet Attacks via Persistent Billable State in Tool-Calling Agents
September 25, 2026
Malicious tools can exploit host runtimes to inject untrusted data into later model turns, creating persistent billable state. Testing via DOW-BENCH showed cumulative input can reach 14,293x the initial call, enabling severe denial-of-wallet attacks against LLM agents.
HOW THIS AFFECTS YOU
●
builderYou must implement strict history-policy boundaries to prevent tool-driven cost explosions.
●
policyThis highlights a critical security gap in how agent runtimes manage token billing and state retention.