The hype cycle loves a dramatic AI failure, but reality is often a boring bug in the plumbing. Pink Agentic AI Payments, a new MCP server and REST API designed to gate AI agent spending, launched a public challenge on October 7 to break their rule engine. They expected days of effort. Instead, the entire $300 bounty was claimed within 4.5 hours on Saturday, October 10, by three researchers who didn't even bother using an AI agent. They just used curl.

The Trailing Space That Cost $100

The first breach, reported by @ins0x4nur4g, exploited a lack of strict input validation. The system had a rule requiring CFO approval for payments over $1,000. The attacker submitted a payment for EUR 999 but included a trailing space in the currency field: "EUR ". The pricing engine failed to recognize the padded code and defaulted to a 1:1 USD exchange rate, approving the transaction as $999. In reality, that was approximately $1,079. The fix was implemented within 70 minutes, enforcing a strict allow-list for currency codes.

Timezone Chaos and UTC Drift

The second vulnerability, also from @ins0x4nur4g, revealed a classic timezone mismatch. A rule restricted payments to 06:00โ€“23:00 Singapore Time (SGT). However, the server evaluated the time against UTC. At 02:07 SGT (well outside the allowed window), a $1,000 payment cleared because the server thought it was 18:07 UTC. Additionally, clients could override the time check by passing a local_hour field. Pink has since attached explicit timezones to workspaces and disabled client-side time overrides for live transactions.

Half a Cent and the Rounding Gap

The final win came from statistician @kimutaiRop, who exploited a rounding discrepancy. A rule auto-approved amounts under $500. The attacker submitted $500.0001. The rule logic rounded the amount to the nearest cent ($500.00) for comparison, but the issued credential retained the unrounded $500.0001 value. While the financial impact was negligible, it highlighted a critical mismatch between validation logic and execution state. Pink paid the $100 bounty to encourage reporting of even minor logic flaws, with a fix for decimal precision rejection currently in progress.

Key Takeaways

  • Validate inputs with strict allow-lists; never rely on fallback defaults for unknown values like currency codes.
  • Always use server-side time evaluation in the specific timezone defined by the workspace rules, ignoring client-provided timestamps.
  • Ensure that the value used for rule evaluation is identical to the value embedded in the final credential to prevent rounding exploits.
  • AI agents are not the only attack surface; standard API input validation remains the first line of defense in agentic payments.

The Bottom Line

If your AI agent payment system can be broken by a trailing space or a timezone conversion error, you aren't building an AI problem; you're building a legacy API problem with a fancy wrapper. Security in agentic finance starts with boring, rigorous input validation, not prompt injection defenses.