Menu

Post image 1
Post image 2
Post image 3
Post image 4
1 / 4
0

Loopjacking in A2A Implementations: Hijacking Human-in-the-Loop Approvals

Hacker News·about 22 hours ago
#YjeTOk3V
Reading 0:00
15s threshold

In a controlled LangGraph Agent Server test, the approval role received a human-in-the-loop interrupt for mock_wire_transfer(20, approved-vendor) . A separate maker could update the pending thread but could not approve or execute a protected transfer. The maker sent another message through the server's A2A route, replacing the pending call with mock_wire_transfer(2000, attacker-sink) . The approval role submitted its earlier decision for a transfer of 20 units. The mock ledger recorded a transfer of 2,000 units under the approver's authority. The approval role was scripted after the test asserted the exact product view of A. The test measures the product's approval binding, not whether a person would notice a change in a user interface. It used an in-memory server, synthetic identities, a deterministic local model, and a harmless ledger. The public evidence archive preserves the requests, decisions, controls, and exact tested versions.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More