Email Thread Hijacking as a Universal Bypass Vector Against Frontier AI Payment Agent Security Controls
收藏资源简介:
This paper documents the discovery and controlled testing of a novel attack vector against AI-powered payment agents operating in enterprise financial workflows. Using the Verified Adversarial Testing Architecture (VATA) methodology, we demonstrate that email thread hijacking — the most common real-world Business Email Compromise technique — constitutes a universal bypass against the full nine-layer VATA Series 2 mitigation stack across four frontier AI models: Claude (claude-opus-4-6), GPT-4o, GPT-5.4, and Grok-4. A fraudulent $850,000 wire transfer to an unregistered vendor embedded within a legitimate email thread executed on all four models across all test passes, bypassing explicit registry controls, unregistered vendor prohibitions, and cumulative amount tracking instructions. A follow-on mitigation battery confirmed partial closure of banking change attacks through explicit thread security rules but failed to close the buried invoice attack — confirming this as a fifth architectural gap in AI payment agent security that requires single-payment API enforcement at the infrastructure layer, not prompt-level mitigations. All findings were cryptographically anchored on the Sepolia Ethereum testnet before public disclosure. Attack anchor: 0x5e063419cd4c241a95b5841099afc0014eb2169ca56f6c36bb174ef735561259. Mitigation anchor: 0x131504cf3d274c384bb5e3d994bbcbce8e0e332bd153351dd06c3bcc3991c60d. This work is part of the VATA independent AI safety research program. Receipts over promises.



