Data Provenance
RAG poisoning, training-data contamination, tampered document chains.
IDScan.net: More than 153 million scanned driver's licenses handed over at counters were being sold on the dark web
the check ends in a moment, the image does not
Expired Visa EMV contactless cards were shown to pass at checkout
the expiry the terminal reads is never collated against the issuer's signed record
Japan's Ministry of Justice puts voice inside publicity rights
but what it sets out is liability after the fact, not a step that checks consent before anything is generated
7.6 petabytes of Hugging Face training data held 221,303 live secrets
detected and notified, never revoked (Truffle Security)
Speechify verified voice-cloning consent with a single checkbox
CFA asks the FTC and state AGs to investigate
A Copilot for Word document worm turned each generated file into the next carrier
recipients cannot verify the edited document reflects the source data
Japanese police identified 123 sexual-deepfake cases in six months, passing all of last year
no layer verifies the provenance of images made from real people
TikTok's 3 billion AI labels coexisted with a 550-video AI-presenter disinformation operation
the absence of a label is not proof of authenticity (C2PA / CNA)
Ariana Grande: the unreleased tracks were taken from her collaborators' weakest accounts, not from her
impersonation and stale credentials never verified before the action
Ruflo's MCP Bridge: one unauthenticated request opened 233 high-privilege tools, and the memory poisoning survives the patch
tool-call authorization and memory provenance are never verified before execution
Wanchain
a non-injective signed-message encoding let one legitimate signature be reused for a vastly larger withdrawal
Verus-Ethereum bridge
the same entry path was hit again two months later, paying out $7.54M without backing
Ostium
one compromised oracle signer key let "future prices" be accepted as validly signed, draining $18M
Figma
AI content training defaulted on for individuals and small teams, and off for enterprise
Over 40,000 unauthorized likeness and voice posts across major platforms
and a 100% takedown rate did not stop the same person's models from reappearing (JAPRO FY2025 survey)
Aptos: a Move VM type confusion could let one on-chain resource be treated as another (reproduced in a ~$3,000 test environment)
The blockchain security firm Hexens disclosed a critical vulnerability in Aptos's Move VM (the execution environment that processes every sm…
A7A5: a ruble-backed stablecoin moved $110B under sanctions
fully traceable on-chain, yet nothing proves or blocks a sender's sanctions status at transaction time (CertiK / Elliptic)
Sumsub: An 18-Month Undetected Intrusion Into a Support Environment Exposed Customers' Names and Contact Details
Sumsub, a global identity-verification (KYC) vendor, disclosed unauthorized access to an internal support-related environment. In July 2024,…
Secret Network: Deposits From a Forged Channel Went Unverified, Letting Unbacked Wrapped Tokens Be Minted Without Limit
On the IBC bridge connecting Secret Network and Axelar, about $4.67 million in assets was withdrawn despite there being no corresponding bac…
Polymarket: Malicious JavaScript Injected via a Compromised Third-Party Vendor Tricked Users Into Approving Fraudulent Transactions
A user of the prediction-market platform Polymarket opened the legitimate site as usual, approved a transaction, and lost about $3 million w…
Hong Kong deepfake video-call fraud: a real-time deepfake of the CFO and every colleague drove a ~$25.6M transfer
seeing a face and hearing a voice no longer proves the person is actually present (Hong Kong Police / Arup)
IDMerit: the disputed billion-record KYC exposure
an unsecured database was found, but no one can prove whose data it was (Cybernews report, IDMerit denial)
Common Crawl: about 12,000 live credentials embedded in a public corpus used to train LLMs
training-data provenance not verified before ingestion (Truffle Security)
Waymo: the robotaxi drove past a stopped school bus
a driving decision not independently verified before a safety-critical action
Hyundai: driver-assist AI braked on a threat that wasn't there
an AI decision overriding the driver, not independently verified before acting (NHTSA)
NHO Hokkaido Hospitals: assumed shredded, sold online
180,000+ patients' drives slipped through, with no independently verifiable destruction trail
Both Sides Cited Cases That Never Existed
AI-Hallucinated Precedent and Rule 11 Sanctions (N.D. Miss.)
Bright Data SDK: your living-room TV became a relay node for AI-scraping
the origin and consent of collected data and relayed traffic not independently verified (Include Security)
No Check on Who Was Authorized
64 Million Records Within Reach in McDonald's McHire (Paradox.ai)
Reachable Meant Readable
DeepSeek's Unauthenticated ClickHouse Backend Exposure
Internal Data Exfiltrated Without Verifying the Instruction's Origin
EchoLeak in Microsoft 365 Copilot (CVE-2025-32711)
Generated Until the Rightsholder Said No
The Consent-and-Provenance Gap Behind OpenAI Sora 2
Tesla Robotaxi Crash Records
Control Attribution and Narrative Provenance Left Self-Reported
Generated Without Consent or Age Verification
The Provenance Gap Behind the Grok Deepfake Controversy
70,000 Government IDs Leaked to Prove Age
Discord's Third-Party Verification Vendor Breach
200 Million Views of Fake Celebrities
The Likeness Provenance Gap Behind YouTube's Deepfake Detection
Phantom Carbon Credits
When an Environmental Attribute Is Issued Without Independent Verification of Its Underlying Data (Operation Greenwashing)
AOG Technics: over 60,000 aircraft engine parts circulated with forged airworthiness certificates
the provenance of the certificates asserting airworthiness is not independently verified before receipt (SFO)
12.8 Billion Training Images Contained Passports, Résumés, and Faces
The Provenance and Consent of Training Data Were Never Verified at Collection
The Inspections Were Recorded as 'Complete'
But Never Performed. On the Boeing 787, the Existence of a Record Was Mistaken for Proof of the Act
Inside a Legitimate Booking Platform, the Payout Bank Account Was Silently Rewritten
The Change Was Not Independently Verified Before Funds Moved (Polaris Holdings / Booking.com)
Stripe's Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data
Allowlists Trust the Domain's Identity, Not the Provenance of What It Carries
Invisible Unicode Instruction Injection
The Gap Between Human-Read and Model-Read Input
OnlyFake
AI-Generated IDs Bypass Exchange KYC
SynthID Watermark, Statistically Stripped
a provenance mark that can be removed and forged (Google DeepMind / Alosh Denny)
Noroboto: embedded "lying fonts" made AI's document review read different text
input-integrity forgery
Discord 2.05 Billion Message Scraping via Public API
How Public Channel Data Gets Redistributed as AI Training Datasets