SoK: Security of Autonomous LLM Agents in Agentic Commerce
2026/04/15 by Qian'ang Mao, Jiaxin Wang, Ya Liu +3 · 1 voice
Computer Science · #cs.CR #cs.MA
paper · pdf
arxiv published 2026/04/15 · arxiv updated 2026/05/01
Abstract
Autonomous large language model (LLM) agents such as OpenClaw are pushing agentic commerce from human-supervised assistance toward machine actors that can negotiate, purchase services, manage digital assets, and execute transactions across on-chain and off-chain environments. Protocols such as the Trustless Agents standard (ERC-8004), Agent Payments Protocol (AP2), OKX Agent Payments Protocol (APP), the HTTP 402-based payment protocol (x402), Agent Commerce Protocol (ACP), the Agentic Commerce standard (ERC-8183), and Machine Payments Protocol (MPP) enable this transition, but they also create an attack surface that existing security frameworks do not capture well. This Systematization of Knowledge (SoK) develops a unified security framework for autonomous LLM agents in commerce and finance. We organize threats along five dimensions: agent integrity, transaction authorization, inter-agent trust, market manipulation, and regulatory compliance. From a systematically curated public corpus of academic papers, protocol documents, industry reports, and incident evidence, we derive 12 cross-layer attack vectors and show how failures propagate from reasoning and tooling layers into custody, settlement, market harm, and compliance exposure. We then propose a layered defense architecture addressing authorization gaps left by current agent-payment protocols. Overall, our analysis shows that securing agentic commerce is inherently a cross-layer problem that requires coordinated controls across LLM safety, protocol design, identity, market structure, and regulation. We conclude with a research roadmap and a benchmark agenda for secure autonomous commerce.
Citations
- MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
- Secure Autonomous Agent Payments: Verifying Authenticity and Intent in a Trustless Environment
- Security Analysis of Agentic AI Communication Protocols: A Comparative Evaluation
- Inter-Agent Trust Models: A Comparative Study of Brief, Claim, Proof, Stake, Reputation and Constraint in Agentic Web Protocol Design-A2A, AP2, ERC-8004, and Beyond
- Delegated Authorization for Agents Constrained to Semantic Task-to-Scope Matching
- Check Yourself Before You Wreck Yourself: Selectively Quitting Improves LLM Agent Safety
- GuruAgents: Emulating Wise Investors with Prompt-Guided LLM Agents
- When Hallucination Costs Millions: Benchmarking AI Agents in High-Stakes Adversarial Financial Markets
- FinDebate: Multi-Agent Collaborative Intelligence for Financial Analysis
- Agentic JWT: A Secure Delegation Protocol for Autonomous AI Agents
- Trading-R1: Financial Trading with LLM Reasoning via Reinforcement Learning
- When FinTech Meets Privacy: Securing Financial LLMs with Differential Private Fine-Tuning
- Secure Multi-LLM Agentic AI and Agentification for Edge General Intelligence by Zero-Trust: A Survey
- Fortifying the Agentic Web: A Unified Zero-Trust Architecture Against Logic-layer Threats
- Modeling and Detecting Company Risks from News: A Case Study in Bloomberg News
- From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
- A Survey of LLM-Driven AI Agent Communication: Protocols, Security Risks, and Defense Countermeasures
- Human-Centred AI in FinTech: Developing a User Experience (UX) Research Point of View (PoV) Playbook
- Seven Security Challenges That Must be Solved in Cross-domain Multi-agent LLM Systems
- Can LLM-based Financial Investing Strategies Outperform the Market in Long Run?
- Build Agent Advocates, Not Platform Agents
- Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents
- SAGA: A Security Architecture for Governing AI Agentic Systems
- From Deep Learning to LLMs: A survey of AI in Quantitative Investment
- Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents
- LLM-Powered Multi-Agent System for Automated Crypto Portfolio Management
- Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems
- Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
- 'Finance Wizard' at the FinLLM Challenge Task: Financial Text Summarization
- Large Language Model Agent in Financial Trading: A Survey
- FinCon: A Synthesized LLM Multi-Agent System with Conceptual Verbal Reinforcement for Enhanced Financial Decision Making
- AI Agents That Matter
- A Survey of Large Language Models for Financial Applications: Progress, Prospects and Challenges
- SuperCLUE-Fin: Graded Fine-Grained Analysis of Chinese LLMs on Diverse Financial Tasks and Applications
- Construction of a Japanese Financial Benchmark for Large Language Models
- FinLlama: Financial Sentiment Classification for Algorithmic Trading Applications
- Automatic and Universal Prompt Injection Attacks against Large Language Models
- Revolutionizing Finance with LLMs: An Overview of Applications and Insights
- Identifying the Risks of LM Agents with an LM-Emulated Sandbox
- Adversarial Deep Hedging: Learning to Hedge without Price Process Modeling
- SoK: Design, Vulnerabilities, and Security Measures of Cryptocurrency Wallets
- Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
Discussions
Related