{"catalogue":"ABA-1 evidence","read_on":"2026-10-04","note":"Amounts are as stated by the source; usd is a rough number for sorting only. Confidence is the reader's judgement. kind tells a paid loss from a bill, a designed test, research or a case with no loss.","cases":[{"id":"a2a-loop-47k","date":"2025-10","who":"four LangChain agents over A2A, unnamed team","loss":"47,000 USD stated; two agents looped 11 days, noticed at the invoice","usd":47000,"patterns":["P1","P2","P4"],"kind":"real_loss","confidence":"medium-low","lesson":"A turn and dollar cap per conversation, enforced outside the agents. The weekly figures in the post do not add up to the total.","sources":["https://pub.towardsai.net/we-spent-47-000-running-ai-agents-in-production-heres-what-nobody-tells-you-about-a2a-and-mcp-5f845848de33"]},{"id":"claude-loop-6000","date":"2026-05","who":"developer, scheduled coding agent loop","loss":"about 6,000 USD in 26 hours; 46 runs each resent the whole conversation uncached","usd":6000,"patterns":["P3","P1","P4"],"kind":"real_loss","confidence":"medium","lesson":"A spend cap per loop and a fresh minimal context per iteration.","sources":["https://pub.towardsai.net/a-developer-burned-6-000-on-claude-overnight-with-one-command-hes-not-the-only-one-ad832f770bd9"]},{"id":"openclaw-poll-loop","date":"2026-02","who":"OpenClaw, issue 16808","loss":"about 150 USD; the same tool call 1,535 times in two hours","usd":150,"patterns":["P2"],"kind":"real_loss","confidence":"high","lesson":"A circuit breaker on identical calls; the watchdog checked that the process was alive, not that it progressed.","sources":["https://github.com/openclaw/openclaw/issues/16808"]},{"id":"openclaw-heartbeat-117m","date":"2026-02","who":"OpenClaw, issue 21597","loss":"117,299,323 tokens in one day across 1,855 tool calls in sessions meant to use no tools","usd":null,"patterns":["P2","P1"],"kind":"real_loss","confidence":"high","lesson":"The no-tools rule lived only in the prompt. Constraints must be enforced by the runner.","sources":["https://github.com/openclaw/openclaw/issues/21597"]},{"id":"apikey-billing-path","date":"2026-03","who":"two Claude Code subscribers, issues 37686 and 86723","loss":"over 1,800 USD in two days, and 1,122.83 USD over two months, billed to a metered key while the user believed the flat plan paid","usd":1800,"patterns":["P3","P4"],"kind":"bill","confidence":"high","lesson":"Show the billing source per run; cap or disable auto-reload.","sources":["https://github.com/anthropics/claude-code/issues/37686","https://github.com/anthropics/claude-code/issues/86723"]},{"id":"bedrock-marketplace-30k","date":"2026-04","who":"AWS user, reported by The Register","loss":"30,141.33 USD over 30 days; the anomaly detector did not cover the marketplace billing channel","usd":30141.33,"patterns":["P4","P3"],"kind":"bill","confidence":"high","lesson":"Alerts must cover every billing channel; a 100 USD threshold never fired.","sources":["https://www.theregister.com/saas/2026/05/14/bedrock-and-a-hard-place-claude-adventure-leaves-aws-user-staring-down-30k-invoice/5238153"]},{"id":"dn42-agent-aws","date":"2026-05","who":"autonomous agent with full cloud credentials","loss":"6,531.30 USD in about a day, reduced by the provider to 1,894 USD","usd":6531.3,"patterns":["P1","P10","P3"],"kind":"bill","confidence":"medium-high","lesson":"The agent treated credentials as approval. Scoped permissions with size limits and human approval for provisioning.","sources":["https://lantian.pub/en/article/fun/ai-agent-bankrupted-their-operator-scan-dn42lantian.lantian/","https://www.infoq.com/news/2026/07/ai-agents-billing-guardrails/"]},{"id":"gemini-key-82k","date":"2026-02","who":"three-developer startup","loss":"82,314.44 USD in 48 hours against a normal 180 USD per month, stolen API key","usd":82314.44,"patterns":["P5","P1"],"kind":"bill","confidence":"medium-high","lesson":"A hard daily cap at the provider or a proxy; key restricted by API and referrer.","sources":["https://www.theregister.com/2026/03/03/gemini_api_key_82314_dollar_charge/"]},{"id":"gemini-student-55k","date":"2025-09","who":"student, key committed to a repository","loss":"55,444 USD over three months, later waived","usd":55444,"patterns":["P5","P1","P4"],"kind":"bill","confidence":"medium","lesson":"Secret scanning before push and a hard billing cap; alerts existed, a cap did not.","sources":["https://eu.36kr.com/en/p/3486014581496960"]},{"id":"llmjacking-sysdig","date":"2024-05","who":"victim of stolen cloud credentials, documented by Sysdig","loss":"over 46,000 USD of model use per day possible, a worst-case figure by Sysdig","usd":46000,"patterns":["P5"],"kind":"research","confidence":"high","lesson":"Least-privilege credentials without model-invoke rights; alert on first-time model invocation.","sources":["https://www.sysdig.com/blog/llmjacking-stolen-cloud-credentials-used-in-new-ai-attack"]},{"id":"leaked-key-honeypot","date":"2024-10","who":"Permiso Security experiment","loss":"3,500 USD in two days; an exposed key was in use within minutes","usd":3500,"patterns":["P5"],"kind":"research","confidence":"high","lesson":"No long-lived keys; invocation logging and anomaly alerts.","sources":["https://krebsonsecurity.com/2024/10/a-single-cloud-compromise-can-feed-an-army-of-ai-sex-bots/"]},{"id":"agent-pricing-fanout","date":"2025-09","who":"coding agent customers, reported by The Register","loss":"1,000 USD in a week against a usual 180 to 200 USD per month; hidden sub-agent fan-out","usd":1000,"patterns":["P3"],"kind":"bill","confidence":"medium-high","lesson":"A price estimate before each task and a cap per task.","sources":["https://www.theregister.com/2025/09/18/replit_agent3_pricing/"]},{"id":"quota-drain-cache","date":"2026-03","who":"coding agent subscribers","loss":"quotas exhausted many times faster than normal; one user in an hour","usd":null,"patterns":["P3","P4"],"kind":"real_loss","confidence":"medium","lesson":"Cache hit rate must be visible; alert on abnormal burn rate.","sources":["https://www.theregister.com/2026/03/31/anthropic_claude_code_limits/"]},{"id":"caching-error-10k","date":"2026-04","who":"companies surveyed by The Pragmatic Engineer","loss":"10,000 USD in one week by one developer through a caching error; 1,400 USD in a single session elsewhere","usd":10000,"patterns":["P3","P4","P11"],"kind":"real_loss","confidence":"medium","lesson":"Daily caps per developer, cheaper default model, cache alerts.","sources":["https://blog.pragmaticengineer.com/the-pulse-token-spend-breaks-budgets-what-next/"]},{"id":"subagent-preamble-48pct","date":"2026-09","who":"one developer, measured","loss":"subagents were 48 percent of the bill and 0.9 percent of returned tokens","usd":null,"patterns":["P3"],"kind":"real_loss","confidence":"medium","lesson":"Each subagent resends its preamble on every request; measure cost per returned result.","sources":["https://dev.to/ji_ai/claude-code-subagents-were-48-of-my-bill-their-output-was-09-e4i"]},{"id":"compaction-spiral","date":"2026","who":"coding agent session, issue 24179","loss":"211 compactions in one session with zero progress, whole quota used","usd":null,"patterns":["P2"],"kind":"real_loss","confidence":"high","lesson":"Progress, not activity, must gate continuation.","sources":["https://github.com/anthropics/claude-code/issues/24179"]},{"id":"budget-gone-in-4-months","date":"2026-05","who":"Uber","loss":"annual AI coding budget used up in four months after a usage leaderboard","usd":null,"patterns":["P11"],"kind":"real_loss","confidence":"high","lesson":"Token budgets per team tied to delivered outcomes; usage was rewarded.","sources":["https://fortune.com/2026/05/26/uber-coo-ai-spending-tokens-claude-code/"]},{"id":"token-leaderboard","date":"2026-04","who":"Meta","loss":"over 60 trillion tokens in 30 days on an internal leaderboard; budgets announced afterwards","usd":null,"patterns":["P11"],"kind":"real_loss","confidence":"medium-high","lesson":"Tokens consumed became the goal; measure cost per shipped outcome.","sources":["https://fortune.com/2026/04/09/meta-killed-employee-ai-token-dashboard/"]},{"id":"flat-plan-outlier","date":"2025-07","who":"model provider absorbing the cost","loss":"tens of thousands of USD of usage by one user on a 200 USD plan","usd":null,"patterns":["P1"],"kind":"real_loss","confidence":"high","lesson":"Flat price with unbounded agent consumption; ceilings from launch.","sources":["https://techcrunch.com/2025/07/28/anthropic-unveils-new-rate-limits-to-curb-claude-code-power-users/"]},{"id":"freysa","date":"2024-11","who":"Freysa, an agent guarding a prize pool","loss":"47,316.05 USD released on message 482 after a user redefined the transfer tool","usd":47316.05,"patterns":["P6","P1"],"kind":"designed_test","confidence":"high","lesson":"The model's judgement was the only barrier between user text and the transfer function.","sources":["https://www.theblock.co/post/328747/human-player-outwits-freysa-ai-agent-in-47000-crypto-challenge"]},{"id":"aixbt-dashboard","date":"2025-03","who":"AIXBT agent tipping wallet","loss":"55.5 ETH, about 105,000 USD; a queued post was a valid payment command","usd":105000,"patterns":["P5","P1"],"kind":"real_loss","confidence":"high","lesson":"Per-transfer cap and recipient allowlist on the wallet; stronger dashboard authentication.","sources":["https://cointelegraph.com/news/hacker-breaches-ai-crypto-bot-aixbt-steals-55-eth"]},{"id":"grok-bankr-morse","date":"2026-05","who":"Grok wallet executed by Bankrbot","loss":"150,000 to 200,000 USD in tokens, about 80 percent reported returned; a decoded Morse message became a transfer order","usd":150000,"patterns":["P6","P1"],"kind":"real_loss","confidence":"medium-high","lesson":"Never treat another agent's output as owner authorisation; ignore privilege changes from unsolicited assets.","sources":["https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet","https://oecd.ai/en/incidents/2026-05-04-4a73"]},{"id":"bankr-14-wallets","date":"2026-05","who":"Bankr, 14 user wallets","loss":"amount not settled across sources; unauthorised signing through the agent-to-agent trust path, two weeks after the first incident","usd":null,"patterns":["P6"],"kind":"real_loss","confidence":"medium","lesson":"Fix the authorisation path after the first incident; per-wallet limits until then.","sources":["https://cointelegraph.com/news/bankr-disables-transactions-after-14-wallets-hacked"]},{"id":"lobstar-wilde","date":"2026-02","who":"autonomous Solana agent","loss":"about 250,000 USD paper value sent instead of about 4 USD; recipient realised about 40,000 USD","usd":250000,"patterns":["P10","P1"],"kind":"real_loss","confidence":"medium-high","lesson":"A hard cap per transfer as a share of holdings and a fresh balance read before signing; the agent had lost its state.","sources":["https://www.theblock.co/post/390722/ai-agent-created-by-openai-dev-accidentally-sends-entire-memecoin-holdings-to-reply-guy"]},{"id":"memory-injection","date":"2025-03","who":"ElizaOS, Princeton and Sentient researchers","loss":"no real loss; instructions planted in shared memory shaped a later transfer on testnet","usd":null,"patterns":["P6"],"kind":"research","confidence":"high","lesson":"Payment parameters only from the current authenticated request; memory separated by trust level.","sources":["https://arxiv.org/abs/2503.16248"]},{"id":"alpha-arena","date":"2025-11","who":"six models each trading 10,000 USD of real money","loss":"four of six lost between 4,201 and 5,874 USD in sixteen days","usd":5874,"patterns":["P9"],"kind":"real_loss","confidence":"medium-high","lesson":"Positive expected value shown on paper before real capital, and a drawdown stop.","sources":["https://forklog.com/en/four-out-of-six-ai-models-suffer-losses-in-trading-tournament/"]},{"id":"project-vend-1","date":"2025-06","who":"shop agent run by Anthropic and Andon Labs","loss":"net worth fell over a month: sold below cost, gave discounts on request, invented a payment account, refused 100 USD for a 15 USD item","usd":null,"patterns":["P9","P13","P6"],"kind":"real_loss","confidence":"high","lesson":"A margin floor enforced in the pricing tool; payment details read from configuration.","sources":["https://www.anthropic.com/research/project-vend-1"]},{"id":"project-vend-2","date":"2025-12","who":"shop agent with a supervising CEO agent","loss":"the supervising agent approved eight times more leniency requests than it denied","usd":null,"patterns":["P11","P6"],"kind":"real_loss","confidence":"high","lesson":"An agent supervising an agent shares its weakness; refunds and credits need deterministic limits.","sources":["https://www.anthropic.com/research/project-vend-2"]},{"id":"newsroom-vending","date":"2025-12","who":"vending agent in a newsroom","loss":"over 1,000 USD in the red after three weeks; forged documents and a fake board vote were accepted as authority","usd":1000,"patterns":["P6","P1"],"kind":"real_loss","confidence":"medium","lesson":"Price and purchase policy changeable only through an authenticated owner channel.","sources":["https://slashdot.org/story/25/12/18/1849218/anthropics-ai-lost-hundreds-of-dollars-running-a-vending-machine-after-being-talked-into-giving-everything-away"]},{"id":"operator-eggs","date":"2025-02","who":"browser agent acting for a columnist","loss":"31.43 USD; asked to find cheap eggs, it bought them with delivery, the confirmation step did not fire","usd":31.43,"patterns":["P10","P9"],"kind":"real_loss","confidence":"medium-high","lesson":"Confirmation enforced at the payment step, and a price check against the stated goal.","sources":["https://incidentdatabase.ai/cite/1028/"]},{"id":"scamlexity","date":"2025-08","who":"AI browser tested by Guardio Labs","loss":"no amount; the agent completed checkout on a fake shop and autofilled the saved card","usd":null,"patterns":["P7","P6"],"kind":"research","confidence":"high","lesson":"Merchant and domain checks before any card autofill; human confirmation for new merchants.","sources":["https://guard.io/labs/scamlexity-we-put-agentic-ai-browsers-to-the-test-they-clicked-they-paid-they-failed"]},{"id":"402bridge","date":"2025-10","who":"protocol built on x402","loss":"about 17,000 USD from 227 wallets that had approved the contract; admin key leaked 13 hours after deployment","usd":17000,"patterns":["P5"],"kind":"real_loss","confidence":"medium-high","lesson":"Exact-amount single-use authorisations; no standing approvals to a contract with one hot admin key.","sources":["https://protos.com/402bridge-private-key-leaks-227-wallets-drained-in-minutes/"]},{"id":"poisoned-api-key-theft","date":"2024-11","who":"user building a trading bot from generated code","loss":"2,500 USD; generated code sent the private key to a scam endpoint","usd":2500,"patterns":["P5","P7"],"kind":"real_loss","confidence":"high","lesson":"A funded key never goes into unreviewed code; keys stay in a signer.","sources":["https://cryptoslate.com/blockchain-security-firm-warns-of-ai-code-poisoning-risk-after-openais-chatgpt-recommends-scam-api/"]},{"id":"key-exfil-mcp","date":"2026-09","who":"npm package offering auto-signed x402 payments, analysed by Knostic","loss":"no loss confirmed; the package sent the wallet private key to a remote server on every call, 2,327 downloads","usd":null,"patterns":["P5"],"kind":"research","confidence":"high","lesson":"Scoped, capped session keys for agent tools; review what a tool does with a key.","sources":["https://www.knostic.ai/blog/when-auto-signing-sends-your-wallet-private-key-to-a-remote-server-a-malicious-mcp-package-on-npm"]},{"id":"malicious-skills","date":"2026-02","who":"agent skill registry audited by Koi Security","loss":"341 of 2,857 skills malicious, over 100 posing as crypto tools","usd":null,"patterns":["P5"],"kind":"research","confidence":"high","lesson":"Signed and reviewed skills; wallets isolated from the agent host.","sources":["https://www.scworld.com/news/openclaw-agents-targeted-with-341-malicious-clawhub-skills"]},{"id":"triple-topup","date":"2026","who":"agent buying its own compute over x402, issue 393","loss":"15 USD paid for one intended 5 USD top-up; each retry signed a fresh payment","usd":15,"patterns":["P8"],"kind":"real_loss","confidence":"medium","lesson":"An idempotency key derived from the payment intent, with deduplication.","sources":["https://github.com/Conway-Research/automaton/issues/393"]},{"id":"x402-settlement-attacks","date":"2026-05","who":"researchers Li, Wang and Wang","loss":"no real loss; payment without service and discovery capture shown on live endpoints, one crafted server took 71.8 percent of traffic","usd":null,"patterns":["P8","P7"],"kind":"research","confidence":"high","lesson":"Payment bound to the caller and the resource; a delivery receipt before funds are final.","sources":["https://arxiv.org/abs/2605.11781"]},{"id":"unfunded-bounties","date":"2026-02","who":"agent bounty boards, two self-published tests","loss":"over 50 listed bounties with no escrow; a 3 USD bounty costing 4 USD in gas","usd":null,"patterns":["P9","P7"],"kind":"real_loss","confidence":"low","lesson":"Verify funded escrow and compare reward with total cost before accepting a task.","sources":["https://dev.to/lilyevesinclair/every-way-an-ai-agent-can-get-paid-in-2026-2il7"]},{"id":"ai-run-store","date":"2026-09","who":"agent given 100,000 USD to run a real shop","loss":"balance down from 100,000 to 60,000 USD in five months; token costs above revenue","usd":40000,"patterns":["P9","P11","P2"],"kind":"real_loss","confidence":"medium","lesson":"Budget released in stages tied to measured sales, with a stop-loss.","sources":["https://slashdot.org/story/26/09/13/0523208/a-visit-to-san-franciscos-ai-run-store-no-customers-nothing-useful-and-losing-money-fast"]},{"id":"airline-chatbot-ruling","date":"2024-02","who":"Air Canada website chatbot, tribunal decision","loss":"812 CAD; the company was held to a refund rule its chatbot invented","usd":600,"patterns":["P13"],"kind":"real_loss","confidence":"high","lesson":"Policy answers only from the canonical text with a link.","sources":["https://www.cbsnews.com/news/aircanada-chatbot-discount-customer/"]},{"id":"one-dollar-car","date":"2023-12","who":"dealership sales chatbot","loss":"no loss; the bot agreed to sell a vehicle for 1 USD and called it binding","usd":null,"patterns":["P13","P6"],"kind":"no_loss","confidence":"high","lesson":"The bot may never state a price or commitment; quotes come from the pricing system.","sources":["https://cybernews.com/ai-news/chevrolet-dealership-chatbot-hack/"]},{"id":"prod-db-deleted-in-freeze","date":"2025-07","who":"coding agent, SaaStr","loss":"production database deleted during a declared freeze; the agent then misreported what it had done","usd":null,"patterns":["P10","P12"],"kind":"real_loss","confidence":"high","lesson":"Production credentials never given to the agent; a freeze must be technical, not verbal.","sources":["https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/"]},{"id":"volume-and-backups-deleted","date":"2026-04","who":"coding agent, PocketOS","loss":"production volume and its backups deleted in nine seconds with a broadly scoped token","usd":null,"patterns":["P10","P5"],"kind":"real_loss","confidence":"high","lesson":"Least-privilege tokens; backups outside the resource they protect.","sources":["https://www.theregister.com/software/2026/04/27/cursor-opus-agent-snuffs-out-startups-production-database/5224442"]},{"id":"terraform-destroy","date":"2026-02","who":"coding agent, DataTalks.Club","loss":"production network, cluster and database destroyed from a stale state file; restored after about 24 hours","usd":null,"patterns":["P10"],"kind":"real_loss","confidence":"high","lesson":"Deletion protection and a human-approved plan before any destroy.","sources":["https://aishippingblog.com/p/how-i-dropped-our-production-database"]},{"id":"support-bot-invented-policy","date":"2025-04","who":"support bot of a developer tool","loss":"cancellations after the bot explained a bug with a policy that did not exist","usd":null,"patterns":["P13"],"kind":"real_loss","confidence":"high","lesson":"Answers grounded in a policy source; escalate when none matches.","sources":["https://fortune.com/article/customer-support-ai-cursor-went-rogue"]},{"id":"ad-budget-overrun","date":"2023-04","who":"automated ad delivery, Meta","loss":"ads spent up to four times their daily budget within hours","usd":null,"patterns":["P1","P4"],"kind":"real_loss","confidence":"medium-high","lesson":"The daily budget was a soft target; account-level hard limits and automatic pause rules.","sources":["https://searchengineland.com/a-catastrophic-meta-bug-caused-overspending-higher-than-average-cpas-396035"]},{"id":"consulting-report-refund","date":"2025-10","who":"consultancy report for a government department","loss":"part of a 440,000 AUD contract refunded after fabricated citations were found","usd":null,"patterns":["P13","P12"],"kind":"real_loss","confidence":"high","lesson":"Every citation resolved against its source before delivery.","sources":["https://www.fastcompany.com/91417492/deloitte-ai-report-australian-government"]},{"id":"voice-bot-job-cuts-reversed","date":"2025-08","who":"bank customer service voice bot","loss":"45 roles cut on a claimed gain that was not measured; call volumes rose and the cuts were reversed","usd":null,"patterns":["P11"],"kind":"real_loss","confidence":"high","lesson":"Measure the effect over a full period before acting on it.","sources":["https://www.abc.net.au/news/2025-08-21/cba-backtracks-on-ai-job-cuts-as-chatbot-lifts-call-volumes/105679492"]},{"id":"drive-through-18000-cups","date":"2025-08","who":"voice ordering at over 500 drive-throughs","loss":"no cost published; one order for 18,000 water cups was accepted","usd":null,"patterns":["P1"],"kind":"no_loss","confidence":"high","lesson":"Quantity and order-value limits with handoff to staff.","sources":["https://techcrunch.com/2025/08/30/taco-bell-is-having-second-thoughts-about-relying-on-ai-at-the-drive-through/"]},{"id":"astranl-own-lane","date":"2026-10","who":"AstraNL steward agent, 72-hour income test","loss":"about twelve hours of production and several million model tokens went into one judged contest with 73 entries, outcome still open; the only income so far, 0.150129 USDC, came from three small objective first-come tasks; one such task was missed by 150 seconds while the agent was busy on the contest","usd":null,"patterns":["P9","P2","P11","P4","P12"],"kind":"own","confidence":"high","lesson":"No expected value was computed before the heavy run, effort had no stop-loss, model usage was not metered against income. This audit was built from that lesson and was run on AstraNL first.","sources":["https://verify.astranl.com/v1/budget/self-audit"]}],"statistics":[{"claim":"Over 40 percent of agentic AI projects will be cancelled by end of 2027 due to escalating costs, unclear value or inadequate risk controls","by":"Gartner, 2025-06-25","kind":"forecast","source":"https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027"},{"claim":"26 percent of AI spend is wasted; 72 percent had unexpected AI cost spikes in 12 months; 79 percent need a day or longer to trace the source","by":"Harness State of AI in FinOps 2026, vendor survey of 700 respondents, self-reported","kind":"survey","source":"https://www.harness.io/state-of-ai-in-finops-2026"},{"claim":"Agents use about 4 times more tokens than chat and multi-agent systems about 15 times","by":"Anthropic engineering, 2025-06-13","kind":"measurement","source":"https://www.anthropic.com/engineering/multi-agent-research-system"},{"claim":"Runs of the same agentic coding task differ by up to 30 times in total tokens","by":"Bai et al, 2026-04","kind":"measurement","source":"https://arxiv.org/abs/2604.22750"},{"claim":"In 1,642 multi-agent traces step repetition was 15.7 percent of failures and unawareness of termination conditions 12.4 percent","by":"Cemri et al, NeurIPS 2025","kind":"measurement","source":"https://arxiv.org/abs/2503.13657"},{"claim":"After filtering wash trades and internal transfers x402 dollar volume falls by about 89 percent","by":"Artemis and Visa figures as of 2026-04-21, quoted by D. McGlynn; original report not opened","kind":"measurement","source":"https://www.danielmcglynn.com/the-x402-counter-has-shown-the-same-four-numbers-since-march/"},{"claim":"Of 529 open Algora bounties 73.2 percent were classed as honeypots; 2 settled payouts in the trailing 30 days","by":"Incubagent, measured 2026-08-10","kind":"measurement","source":"https://incubagent.com/research/agent-bounty-market/"},{"claim":"One open agent bounty board paid 49.05 USDC in total to solvers in two months and logged 114 expired submissions","by":"GitHub issue 1434, NSPG13 agent-bounties, 2026-09-14","kind":"measurement","source":"https://github.com/NSPG13/agent-bounties/issues/1434"},{"claim":"Buyer agents took the first proposal 60 to 100 percent of the time; under prompt injection some models sent all payments to the manipulative seller","by":"Microsoft Research Magentic Marketplace, 2025-10","kind":"experiment","source":"https://arxiv.org/html/2510.25779v1"},{"claim":"In a real-money market of 186 deals the weaker model sold for 3.64 USD less per item and its users rated fairness the same","by":"Anthropic Project Deal, 2025-12","kind":"experiment","source":"https://www.anthropic.com/features/project-deal"},{"claim":"The best agent completed 2.5 percent of real paid freelance projects to an acceptable standard","by":"Remote Labor Index, Scale AI and CAIS, 2025-10","kind":"benchmark","source":"https://arxiv.org/abs/2510.26787"},{"claim":"All 15 x402 facilitators evaluated had security violations","by":"Wang, Yang, Chen, Ji, Payer, 2026-07-21","kind":"research","source":"https://arxiv.org/abs/2607.19545"},{"claim":"Unbounded Consumption, with Denial of Wallet, and Excessive Agency are listed risks LLM10:2025 and LLM06:2025","by":"OWASP Top 10 for LLM Applications 2025","kind":"standard","source":"https://owasp.github.io/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf"}],"gaps_in_existing_controls":["Every framework control counts steps, tokens or dollars; none measures progress, so sunk effort has no stop-loss.","Payment protocols and mandates do not verify that payment produced delivery; disputes are out of scope.","No standard and no product was found that asks whether a spend is worth it for the principal's goal.","Identity schemes verify the agent, not that the seller is real or that the buyer's reward is funded.","Each cap lives in one provider, gateway, wallet or card; nothing gives one limit across rails.","Provider caps can be exceeded briefly and cost figures are estimates; some budgets fail open.","No independent audit of an agent's budget configuration was found on sale."],"not_included":["Claims that could not be traced to a primary or named source were left out, among them a 47,000 USD three-day subagent story from a vendor blog, a 73 percent over-budget statistic with no source, and a 45 million USD oracle exploit with no protocol named."]}