Persistent Billable State: Denial-of-Wallet Attacks and Defenses in Tool-Calling LLM Agents
cs.CR, cs.AI
Submitted: 2026-09-23
Updated: 2026-09-23
Terminology
Sources
- State of AI: An Empirical 100 Trillion Token Study with OpenRouter
- Design Patterns for Securing LLM Agents against Prompt Injections
- Talk is (Not) Cheap: A Taxonomy and Benchmark Coverage Audit for LLM Attacks
- Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
- Token Budgets: An Empirical Catalog of 63 LLM-Agent Budget-Overrun Incidents, with an Affine-Typed Rust Mitigation as a Case Study
- Overthinking Loops in Agents: A Structural Risk via MCP Tools
- Prompt Injection attack against LLM-integrated Applications
- Agent Contracts: A Formal Framework for Resource-Bounded Autonomous AI Systems
- Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks
- LeechHijack: Covert Computational Resource Exploitation in Intelligent Agent Systems
- The Landscape of Prompt Injection Threats in LLM Agents: From Taxonomy to Analysis
- Beyond Max Tokens: Stealthy Resource Amplification via Tool Calling Chains in LLM Agents
- A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems
- From Shield to Target: Denial-of-Service Attacks on LLM-Based Agent Guardrails
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs