Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Category archive
Lemma Critical Brief · Category archive

Data Provenance

RAG poisoning, training-data contamination, tampered document chains.

47 Briefs
No. 141 · 2026-09-04

IDScan.net: More than 153 million scanned driver's licenses handed over at counters were being sold on the dark web

the check ends in a moment, the image does not

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass KYC / AML DisclosureData Provenance Brief →
No. 135 · 2026-08-21

Expired Visa EMV contactless cards were shown to pass at checkout

the expiry the terminal reads is never collated against the issuer's signed record

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & AuthData Provenance Brief →
No. 127 · 2026-08-07

Japan's Ministry of Justice puts voice inside publicity rights

but what it sets out is liability after the fact, not a step that checks consent before anything is generated

Pillar 01 Verifiable Origin Data Provenance Attribute Proof BypassIdentity & Auth Brief →
No. 122 · 2026-08-04

7.6 petabytes of Hugging Face training data held 221,303 live secrets

detected and notified, never revoked (Truffle Security)

Pillar 01 Verifiable Origin Training Data Provenance Code ProvenanceData Provenance Brief →
No. 117 · 2026-08-03

Speechify verified voice-cloning consent with a single checkbox

CFA asks the FTC and state AGs to investigate

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & AuthData Provenance Brief →
No. 118 · 2026-08-03

A Copilot for Word document worm turned each generated file into the next carrier

recipients cannot verify the edited document reflects the source data

Pillar 01 Verifiable Origin Data Provenance AI Decision IntegrityAgent Infrastructure Brief →
No. 119 · 2026-08-03

Japanese police identified 123 sexual-deepfake cases in six months, passing all of last year

no layer verifies the provenance of images made from real people

Pillar 01 Verifiable Origin Data Provenance Attribute Proof BypassIdentity & Auth Brief →
No. 120 · 2026-08-03

TikTok's 3 billion AI labels coexisted with a 550-video AI-presenter disinformation operation

the absence of a label is not proof of authenticity (C2PA / CNA)

Pillar 01 Verifiable Origin Data Provenance Identity & AuthAttribute Proof Bypass Brief →
No. 112 · 2026-07-31

Ariana Grande: the unreleased tracks were taken from her collaborators' weakest accounts, not from her

impersonation and stale credentials never verified before the action

Pillar 01 Verifiable Origin Identity & Auth Data Provenance Brief →
No. 113 · 2026-07-31

Ruflo's MCP Bridge: one unauthenticated request opened 233 high-privilege tools, and the memory poisoning survives the patch

tool-call authorization and memory provenance are never verified before execution

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthData Provenance Brief →
No. 111 · 2026-07-28

Wanchain

a non-injective signed-message encoding let one legitimate signature be reused for a vastly larger withdrawal

Pillar 01 Verifiable Origin Bridge Config Trust Data ProvenanceIdentity & Auth Brief →
No. 107 · 2026-07-24

Verus-Ethereum bridge

the same entry path was hit again two months later, paying out $7.54M without backing

Pillar 01 Verifiable Origin Bridge Config Trust Data ProvenanceIdentity & Auth Brief →
No. 103 · 2026-07-21

Ostium

one compromised oracle signer key let "future prices" be accepted as validly signed, draining $18M

Pillar 01 Verifiable Origin Data Provenance Identity & AuthBridge Config Trust Brief →
No. 106 · 2026-07-21

Figma

AI content training defaulted on for individuals and small teams, and off for enterprise

Pillar 01 Verifiable Origin Training Data Provenance Data ProvenanceAttribute Proof Bypass Brief →
No. 105 · 2026-07-21

Over 40,000 unauthorized likeness and voice posts across major platforms

and a 100% takedown rate did not stop the same person's models from reappearing (JAPRO FY2025 survey)

Pillar 01 Verifiable Origin Data Provenance Training Data ProvenanceAttribute Proof Bypass Brief →
No. 100 · 2026-07-10

Aptos: a Move VM type confusion could let one on-chain resource be treated as another (reproduced in a ~$3,000 test environment)

The blockchain security firm Hexens disclosed a critical vulnerability in Aptos's Move VM (the execution environment that processes every sm…

Pillar 01 Verifiable Origin Code Provenance Bridge Config TrustData Provenance Brief →
No. 093 · 2026-07-03

A7A5: a ruble-backed stablecoin moved $110B under sanctions

fully traceable on-chain, yet nothing proves or blocks a sender's sanctions status at transaction time (CertiK / Elliptic)

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Attribute Proof BypassData Provenance Brief →
No. 086 · 2026-06-30

Sumsub: An 18-Month Undetected Intrusion Into a Support Environment Exposed Customers' Names and Contact Details

Sumsub, a global identity-verification (KYC) vendor, disclosed unauthorized access to an internal support-related environment. In July 2024,…

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Identity & AuthData Provenance Brief →
No. 085 · 2026-06-30

Secret Network: Deposits From a Forged Channel Went Unverified, Letting Unbacked Wrapped Tokens Be Minted Without Limit

On the IBC bridge connecting Secret Network and Axelar, about $4.67 million in assets was withdrawn despite there being no corresponding bac…

Pillar 01 Verifiable Origin Bridge Config Trust Identity & AuthData Provenance Brief →
No. 087 · 2026-06-30

Polymarket: Malicious JavaScript Injected via a Compromised Third-Party Vendor Tricked Users Into Approving Fraudulent Transactions

A user of the prediction-market platform Polymarket opened the legitimate site as usual, approved a transaction, and lost about $3 million w…

Pillar 01 Verifiable Origin Code Provenance Identity & AuthData Provenance Brief →
No. 084 · 2026-06-26

Hong Kong deepfake video-call fraud: a real-time deepfake of the CFO and every colleague drove a ~$25.6M transfer

seeing a face and hearing a voice no longer proves the person is actually present (Hong Kong Police / Arup)

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & AuthData Provenance Brief →
No. 077 · 2026-06-23

IDMerit: the disputed billion-record KYC exposure

an unsecured database was found, but no one can prove whose data it was (Cybernews report, IDMerit denial)

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Data ProvenanceAttribute Proof Bypass Brief →
No. 079 · 2026-06-23

Common Crawl: about 12,000 live credentials embedded in a public corpus used to train LLMs

training-data provenance not verified before ingestion (Truffle Security)

Pillar 01 Verifiable Origin Training Data Provenance Code ProvenanceData Provenance Brief →
No. 042 · 2026-06-17

Waymo: the robotaxi drove past a stopped school bus

a driving decision not independently verified before a safety-critical action

Pillar 02 Verifiable AI AI Decision Integrity Data ProvenanceAI Bias / Harm Brief →
No. 061 · 2026-06-17

Hyundai: driver-assist AI braked on a threat that wasn't there

an AI decision overriding the driver, not independently verified before acting (NHTSA)

Pillar 02 Verifiable AI AI Decision Integrity Data ProvenanceAI Bias / Harm Brief →
No. 065 · 2026-06-17

NHO Hokkaido Hospitals: assumed shredded, sold online

180,000+ patients' drives slipped through, with no independently verifiable destruction trail

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data Provenance Brief →
No. 060 · 2026-06-16

Both Sides Cited Cases That Never Existed

AI-Hallucinated Precedent and Rule 11 Sanctions (N.D. Miss.)

Pillar 02 Verifiable AI AI Decision Integrity Data Provenance Brief →
No. 063 · 2026-06-16

Bright Data SDK: your living-room TV became a relay node for AI-scraping

the origin and consent of collected data and relayed traffic not independently verified (Include Security)

Pillar 01 Verifiable Origin Data Provenance Training Data Provenance Brief →
No. 056 · 2026-06-15

No Check on Who Was Authorized

64 Million Records Within Reach in McDonald's McHire (Paradox.ai)

Pillar 03 Agent Authority Proof Identity & Auth Attribute Proof BypassData ProvenanceAI Bias / Harm Brief →
No. 057 · 2026-06-15

Reachable Meant Readable

DeepSeek's Unauthenticated ClickHouse Backend Exposure

Pillar 03 Agent Authority Proof Identity & Auth Attribute Proof BypassData Provenance Brief →
No. 055 · 2026-06-15

Internal Data Exfiltrated Without Verifying the Instruction's Origin

EchoLeak in Microsoft 365 Copilot (CVE-2025-32711)

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureData Provenance Brief →
No. 054 · 2026-06-13

Generated Until the Rightsholder Said No

The Consent-and-Provenance Gap Behind OpenAI Sora 2

Pillar 01 Verifiable Origin Data Provenance Training Data ProvenanceAttribute Proof Bypass Brief →
No. 049 · 2026-06-12

Tesla Robotaxi Crash Records

Control Attribution and Narrative Provenance Left Self-Reported

Pillar 02 Verifiable AI AI Decision Integrity Data ProvenanceAttribute Proof BypassAI Bias / Harm Brief →
No. 050 · 2026-06-12

Generated Without Consent or Age Verification

The Provenance Gap Behind the Grok Deepfake Controversy

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data ProvenanceAI Decision IntegrityAI Bias / Harm Brief →
No. 052 · 2026-06-12

70,000 Government IDs Leaked to Prove Age

Discord's Third-Party Verification Vendor Breach

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data ProvenanceIdentity & Auth Brief →
No. 053 · 2026-06-12

200 Million Views of Fake Celebrities

The Likeness Provenance Gap Behind YouTube's Deepfake Detection

Pillar 01 Verifiable Origin Data Provenance AI Decision IntegrityAttribute Proof Bypass Brief →
No. 040 · 2026-06-09

Phantom Carbon Credits

When an Environmental Attribute Is Issued Without Independent Verification of Its Underlying Data (Operation Greenwashing)

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data Provenance Brief →
No. 041 · 2026-06-09

AOG Technics: over 60,000 aircraft engine parts circulated with forged airworthiness certificates

the provenance of the certificates asserting airworthiness is not independently verified before receipt (SFO)

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data Provenance Brief →
No. 036 · 2026-06-08

12.8 Billion Training Images Contained Passports, Résumés, and Faces

The Provenance and Consent of Training Data Were Never Verified at Collection

Pillar 01 Verifiable Origin Training Data Provenance Data ProvenanceAttribute Proof Bypass Brief →
No. 035 · 2026-06-08

The Inspections Were Recorded as 'Complete'

But Never Performed. On the Boeing 787, the Existence of a Record Was Mistaken for Proof of the Act

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data ProvenanceIdentity & Auth Brief →
No. 032 · 2026-06-08

Inside a Legitimate Booking Platform, the Payout Bank Account Was Silently Rewritten

The Change Was Not Independently Verified Before Funds Moved (Polaris Holdings / Booking.com)

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data ProvenanceIdentity & Auth Brief →
No. 030 · 2026-06-06

Stripe's Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data

Allowlists Trust the Domain's Identity, Not the Provenance of What It Carries

Pillar 01 Verifiable Origin Code Provenance Identity & AuthData Provenance Brief →
No. 024 · 2026-06-05

Invisible Unicode Instruction Injection

The Gap Between Human-Read and Model-Read Input

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureData Provenance Brief →
No. 022 · 2026-06-04

OnlyFake

AI-Generated IDs Bypass Exchange KYC

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & AuthData Provenance Brief →
No. 011 · 2026-05-31

SynthID Watermark, Statistically Stripped

a provenance mark that can be removed and forged (Google DeepMind / Alosh Denny)

Pillar 01 Verifiable Origin Data Provenance AI Decision Integrity Brief →
No. 005 · 2026-05-30

Noroboto: embedded "lying fonts" made AI's document review read different text

input-integrity forgery

Pillar 02 Verifiable AI AI Decision Integrity Data Provenance Brief →
No. 008 · 2026-05-30

Discord 2.05 Billion Message Scraping via Public API

How Public Channel Data Gets Redistributed as AI Training Datasets

Pillar 01 Verifiable Origin Training Data Provenance Data ProvenanceAttribute Proof Bypass Brief →