Security researchers warned that poisoned or benign-looking external inputs can force LLM applications and autonomous agents into costly reasoning loops, recursive task expansion, retries, and excessive tool use—a denial-of-wallet form of resource exhaustion. Forcepoint’s agent-tool fan-out simulation caused an unprotected research agent to make 500 tool calls at a simulated cost of $10; call budgets, recursion-depth limits, and a circuit breaker reduced this to one call costing $0.02. OWASP now lists unbounded consumption as LLM06:2026, reflecting risks including budget exhaustion, denial of service, and model-extraction activity.
The OverThink research showed that decoy reasoning tasks embedded in external context can preserve apparently correct answers while increasing hidden reasoning-token use by up to 46x in benchmark tests and 17x for coding agents. Related GitInject and OverThink scenarios show that AI-assisted workflows processing untrusted data are susceptible to financially disruptive consumption attacks. Organizations should restrict agent permissions and tools, validate and size-limit external inputs, enforce per-task and aggregate token and spend caps, deploy recursion and circuit breakers, attribute costs to accountable owners, alert on anomalous use, and reconcile provider billing with internal consumption telemetry.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
The fifth revision of the OverThink paper reported evaluations showing reasoning-token increases of up to 13x on FreshQA, 46x on SQuAD, 12x on MuSR, and 17x against coding agents; it also found existing defenses difficult to apply effectively.
OWASP’s 2026 Top 10 for LLM Applications classified unbounded token consumption as LLM06:2026, including denial-of-wallet attacks. The risk rose from No. 10 in the 2025 list to No. 6 in the 2026 list.
Researchers submitted the paper “OverThink: Slowdown Attacks on Reasoning LLMs,” describing benign-looking decoy reasoning problems that can inflate hidden reasoning-token use while preserving correct outputs.
The cited GitInject study examined malicious GitHub issues targeting organizations that use AI agents for error analysis. It estimated that a single attack could create up to $111 in costs and consume 400 minutes of GitHub Actions capacity before GitHub defenses intervene.
Forcepoint simulated poisoned content causing an unprotected research agent to recursively pursue excessive subtopics, make 500 tool calls, and incur a simulated $10 cost. A protected configuration with a call budget, recursion-depth limit, and circuit breaker made one call at a simulated $0.02 cost.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourcekaspersky.ru
Open sourcescworld.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.