Home / Critical Brief / Category archive
Lemma Critical Brief · Category archive

Identity & Auth

Credential leaks, key compromise, authentication bypass.

14 Briefs
No. 009 · 2026-05-31

GTG-1002

The First Reported AI-Orchestrated Espionage Campaign Where the Agent Executed 80–90% Autonomously, and Agent Authority Was Never Independently Verified

Pillar 03 Agent Authority Proof Agent Runaway Identity & Auth Brief →
No. 010 · 2026-05-31

Claude Code Source-Leak Lures

Weaponizing Trust Signals and GitHub Releases as a Provenance-Spoofed Delivery Channel

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 014 · 2026-05-31

The TanStack npm Compromise

Malicious Packages Signed Under a Legitimate OIDC Trusted Publisher, Where a Valid Provenance Signature Did Not Mean a Trustworthy Artifact

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 015 · 2026-05-31

The GitHub Internal Repository Breach

A Poisoned VS Code Extension, Live for 18 Minutes, Exploited the Developer Trust Surface

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 016 · 2026-05-31

The Verus-Ethereum Bridge Hack ($11.58M)

A Valid Merkle Proof, But No Verification That the Source Amount Matched the Payout

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 017 · 2026-05-31

McKinsey Lilli's Writable System Prompts

The Layer Governing the AI's Behavior Had No Integrity or Provenance

Pillar 02 Verifiable AI AI Decision Integrity Identity & AuthAgent Runaway Brief →
No. 012 · 2026-05-31

The Robert Williams Wrongful Arrest

When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification

Pillar 02 Verifiable AI AI Decision Integrity Identity & AuthAI Bias / Harm Brief →
No. 013 · 2026-05-31

The Coinbase KYC Insider Breach

When Regulation-Mandated Storage of Raw PII Becomes the Breach Surface

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Identity & Auth Brief →
No. 003 · 2026-05-30

Starlette CVE-2026-48710 (BadHost)

MCP Server Authentication Bypass via HTTP Host Header Manipulation

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 004 · 2026-05-30

Megalodon GitHub Supply Chain

CI/CD Credential-Theft Campaign That Poisoned 5,561 Repositories in 6 Hours

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 007 · 2026-05-30

Cursor + Claude Opus 4.6 Wiped PocketOS Production DB in 9 Seconds

The Unverified Destructive Authority of AI Coding Agents

Pillar 03 Agent Authority Proof Agent Runaway Identity & Auth Brief →
No. 006 · 2026-05-30

Google API Keys Remain Usable for 23 Minutes After Deletion

Independent Verification Gap in Credential Revocation Attributes

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & Auth Brief →
No. 001 · 2026-05-29

KelpDAO / rsETH Unauthorized Unlock

RPC Manipulation Attack on the DVN Observation Layer

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 002 · 2026-05-29

Stake DAO vsdCRV Unauthorized Mint

LayerZero v2 Trust Source Rewriting via Deployer Key

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →