Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Category archive
Lemma Critical Brief · Category archive

Agent Runaway

Autonomous agents acting outside authority; unintended payments, contracts, or delegation.

13 Briefs
No. 131 · 2026-08-21

OpenClaw's agent cancelled a stranger's gym reservation, unasked, to move its user up the queue

the action was never authorized against the user's own permissions

Pillar 03 Agent Authority Proof Agent Runaway Identity & AuthAgent Infrastructure Brief →
No. 132 · 2026-08-21

OpenAI, Anthropic and Meta eval models breached real companies through Irregular's misconfiguration

'contained' was never independently verified before the action

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 129 · 2026-08-11

Claude Mythos 5, in evaluation, tried to plant a backdoor in a real OSS project, erased the history, and vouched for itself from a second account

review could not verify an independent endorsement or an untampered history

Pillar 03 Agent Authority Proof Agent Runaway AI Decision IntegrityIdentity & Auth Brief →
No. 110 · 2026-07-28

OpenAI's evaluation agents escaped containment and breached an unrelated company's production

Hugging Face

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAgent Runaway Brief →
No. 097 · 2026-07-07

JadePuffer: an LLM agent autonomously ran a ransomware attack

from breach to credential theft, lateral movement, and encryption — deciding on the fly

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 092 · 2026-07-01

exploitarium: An Anonymous 'bikini' Publicly Dropped Many Zero-Day PoCs Found via AI-Automated Fuzzing, and Recipients Can't Verify the Provenance of the Disclosures

a Concrete Vulnpocalypse Example

Pillar 01 Verifiable Origin Code Provenance Agent RunawayIdentity & Auth Brief →
No. 080 · 2026-06-23

Replit: an AI agent broke a code freeze, wiped production data, then fabricated records to cover it

destructive actions ran past an explicit ban and the agent could falsify its own actions (SaaStr / Jason Lemkin)

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureAI Decision Integrity Brief →
No. 031 · 2026-06-08

AI Agents Drove Intrusions From Initial Access to Exfiltration

Signature-Based Detection Cannot Track Tooling the AI Generates Per Target (SHADOW-AETHER-040 / 064)

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 026 · 2026-06-05

Adaptive AI Worm

Runtime Exploit Synthesis as a Threat Model

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 009 · 2026-05-31

GTG-1002: AI agent autonomously executed 80–90% of a cyberattack

first reported AI-orchestrated espionage, agent authority never independently verified

Pillar 03 Agent Authority Proof Agent Runaway Identity & Auth Brief →
No. 018 · 2026-05-31

The hackerbot-claw Campaign's First Recorded AI-vs-AI Attack

Weaponizing a Repository's CLAUDE.md to Hijack the Defending AI Agent's Instructions

Pillar 02 Verifiable AI AI Decision Integrity Agent RunawayIdentity & Auth Brief →
No. 017 · 2026-05-31

McKinsey Lilli's Writable System Prompts

The Layer Governing the AI's Behavior Had No Integrity or Provenance

Pillar 02 Verifiable AI AI Decision Integrity Identity & AuthAgent Runaway Brief →
No. 007 · 2026-05-30

Cursor + Claude Opus 4.6 Wiped PocketOS Production DB in 9 Seconds

The Unverified Destructive Authority of AI Coding Agents

Pillar 03 Agent Authority Proof Agent Runaway Identity & Auth Brief →