Loopjacking: How a Pending A2A Update Can Hijack a Human Approval

Loopjacking in A2A Implementations: Hijacking Human-in-the-Loop Approvals

Loopjacking: How a Pending A2A Update Can Hijack a Human Approval

In a controlled LangGraph Agent Server test, a maker replaced a pending wire transfer of 20 units with one of 2,000 units to an attacker sink, then an approver's stale decision released the larger transfer. The attack exploits A2A Task and tool-call IDs that stay the same while arguments change, so an implementation that checks only that a Task was approved can spend that approval on a different operation. The flaw is implementation-side, not a core A2A vulnerability.

The decisive question is which operation reached the sink under A's decision.

More from this day

2026-09-25