A bug in the AI shopping assistant Phia allowed malicious actors to stuff cookies, falsely claiming commissions on purchases the agent didn’t facilitate, according to a report by Inside Retail Asia. The incident exposed how easily attribution systems in AI-driven e-commerce can be exploited, undermining the trust that underpins the growing trend of agentic shopping.
Phia, an AI agent that helps consumers find and purchase products, normally earns commissions from retailers through proper referral links. However, the bug allowed third parties to inject Phia's affiliate cookies without the agent’s involvement, effectively stealing credit for sales. This form of cookie stuffing is notoriously difficult to detect, as it happens on the server side without visible evidence to the retailer or the consumer.
The scandal highlights a larger challenge for the AI commerce ecosystem: verifying that AI agents actually performed the work they claim. As these agents become more autonomous, the industry must develop new attribution mechanisms that are resistant to fraud. The Phia case serves as a cautionary tale for retailers and AI developers alike, emphasizing the need for transparency and security in automated shopping pipelines.