The first verified breach of Pink Agentic AI Payments' spending rules didn't involve sophisticated prompt injection or a rogue LLM agent. It involved a single trailing space character. On 2026-10-10, GitHub user @ins0x4nur4g claimed the first of three $100 bounties offered by the company after launching a public overspend challenge just three days prior. The exploit was simple: sending a payment request with the currency field set to "EUR " instead of "EUR" caused the REST API to misinterpret the transaction's value, bypassing mandatory CFO approval thresholds.
The Exploit Mechanics
Pink Agentic AI Payments operates a rules engine where payments to known vendors under $1,000 are auto-allowed, while amounts between $1,000 and $5,000 require CFO approval. @ins0x4nur4g submitted a request for 999 EUR. However, the trailing space in the currency code prevented the REST endpoint from recognizing it as a valid ISO currency. Instead of rejecting the input, the system fell back to treating the amount as 1:1 USD. Since USD 999 is below the $1,000 threshold, the transaction auto-approved. In reality, 999 EUR was approximately USD 1,079 at the engine's internal rate, meaning the transaction should have triggered a hold.
Validation Drift Between Entry Points
Crucially, this vulnerability existed only in the REST API entry point, not the Model Context Protocol (MCP) server that AI agents typically use. The MCP edge had already implemented a strict currency allowlist, rejecting any input that wasn't an exact match. The rules engine itself was functioning correctly; it simply never received the accurate currency data because the REST layer defaulted to USD for unrecognized codes. This highlights a critical failure in input normalization across different interfaces. The developers confirmed the issue was reproducible on a second agent and maintained discretion regarding the exact trigger details until the fix was deployed.
Rapid Response and Patch Details
Pink Agentic AI Payments shipped a fix within roughly 70 minutes of the report. The updated system now returns an HTTP 400 error for any currency code that is not exactly USD, EUR, GBP, HKD, SGD, or JPY. The engine was also updated to refuse pricing for any unknown currency code, eliminating the dangerous default-to-USD fallback. Additionally, the company unified the validation logic so that REST and MCP endpoints now share a single currency list, preventing future drift. Two secondary fixes were included in the same deploy: improved handling for idempotency keys and automatic rollover for daily and monthly spend counters.
Key Takeaways
- Input normalization must occur in a single source of truth to prevent validation drift between APIs.
- Policy engines should fail closed on unknown inputs rather than applying permissive defaults.
- Public bounty programs effectively uncover edge cases that internal QA often misses.
The Bottom Line
This incident proves that the weakest link in AI agent security isn't usually the model's reasoning, but the sloppy input validation in the plumbing behind it. If your API defaults to USD for unrecognized currencies, you're just waiting for someone to type a space.