We put a $300 bounty on Pink's AI agent spending rules. It was gone by lunch.
We build Pink Agentic AI Payments, an MCP server and REST API that lets an AI agent request a payment, but checks that request against rules a company set up first: budgets, amount limits, which payees are allowed or blocked, what hours it can run, which human has to sign off. Only after a request clears those rules does a single-use credential get issued, locked to that payee and that amount.…
Pink Agentic AI Payments is a sandbox system that allows AI agents to request payments while ensuring they adhere to company rules regarding budgets, amount limits, allowed payees, blocked payees, operating hours, and required human sign-off. The system is currently a public sandbox, using test money only, with no production implementation yet.
On October 7, Pink launched a public challenge: find a way to bypass the system's rules and push a payment through. For the first three verified wins, Pink offered a $300 bounty, with $100 for each win. The bounty was claimed within four and a half hours on October 10, long before lunchtime.
Three separate bugs in the system were exploited to bypass the rules. The first involved a trailing space in the currency field. By adding a space in the EUR currency code (EUR ), the payment was treated as USD and approved, even though the amount exceeded the $1,000 threshold requiring CFO approval. The exploit was fixed within 70 minutes.
The second bug involved time zone discrepancies. A rule specified quiet hours in Singapore Time (SGT), but the server checked the time in UTC. This allowed a payment to pass during quiet hours, even though it occurred outside the specified window. Every workspace now has a timezone attached, and time rules evaluate using the server's clock in that timezone.
The third bug involved rounding mismatches. One rule auto-approved payments at or below $500. However, a payment of $500.0001 was approved because the rule compared against the amount rounded to the cent, while the issued credential carried the unrounded amount. Future updates will reject amounts with more decimal precision than allowed for the currency.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.