Persistent Billable State: Denial-of-Wallet Attacks and Defenses in Tool-Calling LLM Agents
arXiv:2609.28585v1 Announce Type: cross Abstract: Multi-step tool-calling LLM agents rely on host runtimes to preserve state across turns. When a runtime carries an external tool return into later model inputs, providers meter it again. An admitted malicious or compromised tool can thereby convert…