{
  "id": 12244210,
  "title": "8,096 IPs, One WooCommerce Cart Attack: How We Protected the Cart Without Blocking AI Commerce",
  "url": "https://urgent.news/2026/10/05/8-096-ips-one-woocommerce-cart-attack-how-we-protected-the-cart",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T22:35:03.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/zologic/8096-ips-one-woocommerce-cart-attack-how-we-protected-the-cart-without-blocking-ai-commerce-k47"
  },
  "original_language": "en",
  "account": "In a recent incident involving WooCommerce, a store experienced an unusual surge in traffic with suspicious patterns. The traffic appeared impressive, with thousands of sessions and active users, but the engagement was almost zero and revenue was zero. The requests were hitting WooCommerce URLs containing ?add-to-cart=..., indicating an attack on the cart functionality.\n\nInvestigating the situation, the team noticed that blocking the IP addresses or browser User-Agent would have been incorrect solutions. This was because they were actively building infrastructure that allowed legitimate AI shopping agents to interact with WooCommerce. They needed to stop abusive automation without breaking agentic commerce.\n\nThe team examined the server logs and discovered that the requests had a consistent pattern: GET /shop/example-product/?add-to-cart=1234 and sometimes GET /basket/ with the second request arriving only a few seconds after the first. The User-Agent often looked ordinary, but the high volume of requests made it clear that this was not legitimate traffic.\n\nTo address the issue, the team decided to focus on protecting the state transition in WooCommerce rather than blocking specific IP addresses or User-Agent strings. They built a separate WooCommerce protection layer around the legacy GET add-to-cart flow, ensuring that clients could not perform state-changing operations without valid proof. This proof was signed using HMAC and stored in a secure first-party cookie with expiration after five minutes.\n\nBy verifying the signature and age of the proof before processing the legacy add-to-cart operation, the team prevented blind, stateless cart mutations. This approach did not attempt to determine whether the client was human but instead changed the economics and state requirements of the attack.",
  "summary": "A real-world WooCommerce incident involving rotating IPs, browser-like bot traffic, WordPress lifecycle ordering, signed cart proofs, Redis, and keeping UCP/MCP agent commerce online. A WooCommerce store we operate started showing a strange traffic pattern. At first glance, it looked like growth. Traffic increased sharply. The basket page was receiving unusual attention. Google Analytics showed…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}