{"slug": "the-first-person-to-beat-our-ai-agent-s-spending-rules-did-it-with-a-space", "title": "The first person to beat our AI agent's spending rules did it with a space character", "summary": "Pink Agentic AI Payments disclosed that a researcher using the handle @ins0x4nur4g bypassed its AI agent spending rules by submitting a payment request with a trailing space in the currency field (\"EUR \"), which the REST edge failed to recognize and priced 1:1 as USD, slipping a EUR 999 payment under the $1,000 auto-allow threshold and skipping CFO approval. The company reproduced the issue and shipped a fix about 70 minutes after the report, adding a strict currency allowlist to the REST edge to match the MCP edge, which was never affected. The find was the first verified win in the company's public $100-per-win overspend bounty challenge.", "body_md": "We launched a public [overspend challenge](https://github.com/Pink-Agentic-Payments/overspend-challenge?utm_source=devto&utm_medium=article&utm_campaign=win1) on 2026-10-07: find a way to get an AI agent past the spending rules enforced by Pink Agentic AI Payments, our MCP server + REST API + rules engine for giving AI agents controlled spending power. We added a $100 bounty per verified win (first 3 wins, $300 total) on 2026-10-08.\n\nOn 2026-10-10 at 08:50 PT, two days after the bounty went up, GitHub user [@ins0x4nur4g](https://github.com/ins0x4nur4g) opened [issue #1](https://github.com/Pink-Agentic-Payments/overspend-challenge/issues/1). No AI agent, no prompt injection. Plain curl against our REST API.\n\nOur rules engine has a sensible policy: payments to known vendors under $1,000 auto-allow, and anything from $1,000 to $5,000 needs CFO approval. @ins0x4nur4g sent a payment request for an approved EUR vendor with the currency field written as `\"EUR \"`, a trailing space.\n\nThe REST edge didn't recognize the padded code, so it fell back to pricing the amount 1:1 as USD instead of converting it. A EUR 999 payment (about USD 1,079 at the engine's own EUR rate) got read as \"USD 999\", which is under the $1,000 auto-allow line. It skipped CFO approval entirely and got issued a single-use wire credential, test money, in our sandbox. They reproduced it on a second agent to confirm it wasn't a fluke, and kept the exact trigger out of the public issue, sending the details to us privately instead.\n\nRoughly:\n\n```\n// request\n{ \"amount\": 999, \"currency\": \"EUR \" }\n\n// before the fix\n// treated as USD 999 -> under $1,000 -> auto-allowed, no CFO hold\n\n// after the fix\n// HTTP 400: unsupported currency 'EUR '; use one of USD, EUR, GBP, HKD, SGD, JPY\n```\n\nThe important detail: the MCP edge, which is what AI agents actually talk to, was never affected. It already enforced a strict currency allowlist. The bug was that our two entry points, REST and MCP, validated input differently. The rules engine itself made the right call every time; it just never got a chance to see the real currency.\n\nSpending-policy engines get good testing on the \"happy path\" values builders expect: `USD`, `EUR`, exact matches. Whitespace, casing, and other near-miss inputs are the kind of thing that doesn't show up until someone deliberately goes looking, which is the entire point of running a public bounty instead of just internal QA.\n\nWe reproduced it the same morning and shipped a fix by about 10:00 PT, roughly 70 minutes after the report:\n\n`USD`, `EUR`, `GBP`, `HKD`, `SGD`, or `JPY`.\nWe re-checked live after deploy: `\"EUR\"` correctly gets held for CFO approval, and `\"EUR \"`, `\" EUR\"`, `\"EURO\"`, and `\"XXX\"` all now return 400.\n\nSame deploy, two smaller fixes worth mentioning: a reused idempotency key with a different payload now correctly returns 409 instead of silently replaying the original request, and daily/monthly spend counters now roll over automatically at the UTC day/month boundary instead of needing a manual reset.\n\nThis wasn't a rules-engine bug. The rules were correct. The input boundary in front of them wasn't. If you're building spending controls for an AI agent, or anything that gates money on a policy engine, three rules we'd pass on:\n\nPink Agentic AI Payments enforces spending rules on the server, in front of the money, so a fix to one rule boundary protects every agent at once.\n\nThank you, @ins0x4nur4g, for finding this cleanly, reproducing it, and keeping the trigger private until the fix was live. That's exactly how this is supposed to work. Issue #1 is now verified as win #1 of 3, and the hall of fame and fix log are updated in the repo.\n\nTwo bounties left, $100 each. If you can get an AI agent, or a plain HTTP client, past our spending rules, [the challenge is open](https://github.com/Pink-Agentic-Payments/overspend-challenge?utm_source=devto&utm_medium=article&utm_campaign=win1).\n\nOur public sandbox is test money only: [https://agentic-sandbox.pinkwallet.com](https://agentic-sandbox.pinkwallet.com). Production isn't live yet; we're running an early-access waitlist.", "url": "https://wpnews.pro/news/the-first-person-to-beat-our-ai-agent-s-spending-rules-did-it-with-a-space", "canonical_source": "https://dev.to/quinn_854b15f517d8632ed4f/the-first-person-to-beat-our-ai-agents-spending-rules-did-it-with-a-space-character-4c6n", "published_at": "2026-10-10 17:10:38+00:00", "updated_at": "2026-10-10 17:18:46.260612+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-tools"], "entities": ["Pink Agentic AI Payments", "@ins0x4nur4g", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/the-first-person-to-beat-our-ai-agent-s-spending-rules-did-it-with-a-space", "markdown": "https://wpnews.pro/news/the-first-person-to-beat-our-ai-agent-s-spending-rules-did-it-with-a-space.md", "text": "https://wpnews.pro/news/the-first-person-to-beat-our-ai-agent-s-spending-rules-did-it-with-a-space.txt", "jsonld": "https://wpnews.pro/news/the-first-person-to-beat-our-ai-agent-s-spending-rules-did-it-with-a-space.jsonld"}}