threat intelligence
× proof layer.
Structured analysis of incidents across AI, cryptographic infrastructure, supply chain, and regulatory attributes — read through the Detection ≠ Proof thesis . Each Brief makes the failure primitive explicit and identifies the structural gap that hardening detection alone cannot close, then connects it to the pre-execution attestation design.
McKinsey Lilli's Writable System Prompts
2026 年 2 月、レッドチーム企業 CodeWall の自律オフェンシブ AI エージェントが、McKinsey の社内向け生成 AI プラットフォーム「Lilli」を、認証情報も内部知識もない状態から 2 時間足らずで本番データベースへの完全な read/write アクセスに到達させた。露呈した最も重大な gap は、Lilli の挙動を統治する 95 件の system prompt がすべて書き込み可能だった点である。攻撃者はこれを悪用すれば、Lilli の回答・…
Verifiable Origin
The layer that independently verifies the origin of messages, data, and code.
The Verus-Ethereum Bridge Hack ($11.58M)
A Valid Merkle Proof, But No Verification That the Source Amount Matched the Payout
The GitHub Internal Repository Breach
A Poisoned VS Code Extension, Live for 18 Minutes, Exploited the Developer Trust Surface
The TanStack npm Compromise
Malicious Packages Signed Under a Legitimate OIDC Trusted Publisher, Where a Valid Provenance Signature Did Not Mean a Trustworthy Artifact
SynthID Watermark Reverse-Engineering
How a Statistical Attack Strips the Provenance Mark from AI-Generated Content
Claude Code Source-Leak Lures
Weaponizing Trust Signals and GitHub Releases as a Provenance-Spoofed Delivery Channel
Discord 2.05 Billion Message Scraping via Public API
How Public Channel Data Gets Redistributed as AI Training Datasets
Megalodon GitHub Supply Chain
CI/CD Credential-Theft Campaign That Poisoned 5,561 Repositories in 6 Hours
Stake DAO vsdCRV Unauthorized Mint
LayerZero v2 Trust Source Rewriting via Deployer Key
KelpDAO / rsETH Unauthorized Unlock
RPC Manipulation Attack on the DVN Observation Layer
Verifiable AI
The layer that ZK-commits the process of AI judgment.
McKinsey Lilli's Writable System Prompts
The Layer Governing the AI's Behavior Had No Integrity or Provenance
The Robert Williams Wrongful Arrest
When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification
Noroboto Attack
AI Document Review Input-Integrity Forgery via Embedded Lying Fonts
Agent Authority Proof
The layer that records and proves the delegation relationships of agents.
GTG-1002
The First Reported AI-Orchestrated Espionage Campaign Where the Agent Executed 80–90% Autonomously, and Agent Authority Was Never Independently Verified
Cursor + Claude Opus 4.6 Wiped PocketOS Production DB in 9 Seconds
The Unverified Destructive Authority of AI Coding Agents
Starlette CVE-2026-48710 (BadHost)
MCP Server Authentication Bypass via HTTP Host Header Manipulation
Regulatory Attribute Proof
The layer that proves KYC / AML / regulatory attributes via selective disclosure.