threat intelligence
× proof layer.
Structured analysis of incidents across AI, cryptographic infrastructure, supply chain, and regulatory attributes — read through the Detection ≠ Proof thesis . Each Brief makes the failure primitive explicit and identifies the structural gap that hardening detection alone cannot close, then connects it to the pre-execution attestation design.
Stripe's Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data
On June 4, 2026, e-commerce security firm Sansec disclosed a new Magecart (web-skimming) campaign abusing Stripe's API infrastructure. Stripe itself was not breached. The attacker repurposed the trusted domains an online store implicitly al…
Verifiable Origin
The layer that independently verifies the origin of messages, data, and code.
Stripe's Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data
Allowlists Trust the Domain's Identity, Not the Provenance of What It Carries
The npm Dependency-Confusion Recon Campaign
33 Packages Impersonating Internal Scopes Exploit the Build Environment's Provenance Assumptions
The Alephium TokenBridge Exploit ($815K)
Guardian Keys Intact, But No Verification of the Provenance of the Events They Signed
The Verus-Ethereum Bridge Hack ($11.58M)
A Valid Merkle Proof, But No Verification That the Source Amount Matched the Payout
The GitHub Internal Repository Breach
A Poisoned VS Code Extension, Live for 18 Minutes, Exploited the Developer Trust Surface
The TanStack npm Compromise
Malicious Packages Signed Under a Legitimate OIDC Trusted Publisher, Where a Valid Provenance Signature Did Not Mean a Trustworthy Artifact
SynthID Watermark Reverse-Engineering
How a Statistical Attack Strips the Provenance Mark from AI-Generated Content
Claude Code Source-Leak Lures
Weaponizing Trust Signals and GitHub Releases as a Provenance-Spoofed Delivery Channel
Discord 2.05 Billion Message Scraping via Public API
How Public Channel Data Gets Redistributed as AI Training Datasets
Megalodon GitHub Supply Chain
CI/CD Credential-Theft Campaign That Poisoned 5,561 Repositories in 6 Hours
Stake DAO vsdCRV Unauthorized Mint
LayerZero v2 Trust Source Rewriting via Deployer Key
KelpDAO / rsETH Unauthorized Unlock
RPC Manipulation Attack on the DVN Observation Layer
Verifiable AI
The layer that ZK-commits the process of AI judgment.
Invisible Unicode Instruction Injection
The Gap Between Human-Read and Model-Read Input
The hackerbot-claw Campaign's First Recorded AI-vs-AI Attack
Weaponizing a Repository's CLAUDE.md to Hijack the Defending AI Agent's Instructions
McKinsey Lilli's Writable System Prompts
The Layer Governing the AI's Behavior Had No Integrity or Provenance
The Robert Williams Wrongful Arrest
When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification
Noroboto Attack
AI Document Review Input-Integrity Forgery via Embedded Lying Fonts
Agent Authority Proof
The layer that records and proves the delegation relationships of agents.
One-Click GitHub OAuth Token Theft via github.dev
The Webview Trusted Synthetic Events, and the Token Was Not Scoped to the Repo
LibreChat CVE-2026-32625
User-Supplied MCP Server URLs as an Exfiltration Channel for Server Secrets
Adaptive AI Worm
Runtime Exploit Synthesis as a Threat Model
MCP Design: Config-to-Command Execution and Supply-Chain-Scale RCE
In April 2026, OX Security disclosed that Anthropic's Model Context Protocol (MCP) official SDK contains a design-level issue in which confi…
GTG-1002
The First Reported AI-Orchestrated Espionage Campaign Where the Agent Executed 80–90% Autonomously, and Agent Authority Was Never Independently Verified
Cursor + Claude Opus 4.6 Wiped PocketOS Production DB in 9 Seconds
The Unverified Destructive Authority of AI Coding Agents
Starlette CVE-2026-48710 (BadHost)
MCP Server Authentication Bypass via HTTP Host Header Manipulation
Regulatory Attribute Proof
The layer that proves KYC / AML / regulatory attributes via selective disclosure.
OnlyFake
AI-Generated IDs Bypass Exchange KYC
Forged Balance Confirmations Asserting Asset Existence
A Financial Attribute Asserted Without Independent Verification, Reaching Disclosure and Markets (Wirecard)
Tampered Certification Test Data Behind Type Designation
Product Regulatory-Conformance Attributes Asserted Without Independent Verification on the Path to Shipment
Unqualified Engineers Placed Under National-License Claims
Regulatory Attributes Asserted Without Independent Verification at the Point of Assignment
The Coinbase KYC Insider Breach
When Regulation-Mandated Storage of Raw PII Becomes the Breach Surface
Google API Keys Remain Usable for 23 Minutes After Deletion
Independent Verification Gap in Credential Revocation Attributes