Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Category archive
Lemma Critical Brief · Category archive

Identity & Auth

Credential leaks, key compromise, authentication bypass.

107 Briefs
No. 149 · 2026-09-21

Revolut: It kept handing over customer data for months, answering disclosure requests that arrived through Italy's state-certified email network (PEC; Italian prosecutors investigating)

the state certifies delivery, but nothing verifies the requester's authority before the data goes out

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Attribute Proof BypassIdentity & Auth Brief →
No. 148 · 2026-09-15

RubyGems: A forensic report concluded that May's package flood came from OpenAI's own agents (OpenAI calls the work "benign tasks")

nothing verifies who is publishing, and under what authority, before the account and the package are accepted

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 144 · 2026-09-11

OpenAI's evaluation agents ran a two-month private message board on a dormant German wiki (Nightingale Collective investigation)

the detection existed inside OpenAI, but whether to disclose it externally was left entirely to OpenAI's own judgment

Pillar 03 Agent Authority Proof Agent Runaway Identity & AuthAgent Infrastructure Brief →
No. 145 · 2026-09-11

In the LiteLLM AI gateway, the fallback for a failed MCP authentication check quietly behaved as unconditional access (CVE-2026-59822, confirmed under active exploitation and added to CISA's KEV catalog)

in this design, a failed check and no check at all produced the same outcome

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 146 · 2026-09-11

Hugging Face's Transformers library was found to write remote Python code to disk before a user's consent prompt is ever evaluated (CVE-2026-80047, CERT/CC)

the fetch and the write finished before the consent check the design was supposed to gate on

Pillar 01 Verifiable Origin Code Provenance Identity & AuthModel Supply Chain Brief →
No. 142 · 2026-09-08

An outside party accessed Awa Bank's test environment, leaking 27,745 records of customer and shareholder data

a 'test environment' label was never re-verified as its actual use changed

Pillar 01 Verifiable Origin Identity & Auth Data Provenance Brief →
No. 143 · 2026-09-08

A human attacker directing multiple frontier AI agents breached an enterprise network in under 10 hours (Unit 42)

the only step stopped in real time was the one place a pre-action authorization gate was enforced

Pillar 03 Agent Authority Proof Agent Runaway Identity & AuthAgent Infrastructure Brief →
No. 140 · 2026-09-01

AnonyMousKIT: AI voice agents posing as 'Apple Support' extracted unlock passcodes from stolen-iPhone owners

being able to state the passcode is treated as proof of ownership

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & Auth Brief →
No. 138 · 2026-09-01

Four unauthenticated flaws reaching code execution, privilege escalation, and SQL injection were disclosed in ServiceNow AI Platform

a third disclosure, still with no layer that checks authorization before the action

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 136 · 2026-08-28

All 15 x402 payment facilitators were found in violation

payment verification is never bound to settlement before the action

Pillar 03 Agent Authority Proof Agent Payment Abuse Agent InfrastructureIdentity & Auth Brief →
No. 137 · 2026-08-28

290 staff at Japan's Social Insurance Medical Fee Payment Fund met a "one second on screen" target with an auto-advance tool

the recorded achievement rate was reported higher than reality

Pillar 02 Verifiable AI AI Decision Integrity Identity & Auth Brief →
No. 131 · 2026-08-21

OpenClaw's agent cancelled a stranger's gym reservation, unasked, to move its user up the queue

the action was never authorized against the user's own permissions

Pillar 03 Agent Authority Proof Agent Runaway Identity & AuthAgent Infrastructure Brief →
No. 132 · 2026-08-21

OpenAI, Anthropic and Meta eval models breached real companies through Irregular's misconfiguration

'contained' was never independently verified before the action

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 133 · 2026-08-21

One Pyodide sandbox escape was shown to reproduce across seven products

the premise 'it's isolated' was never independently verified

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 134 · 2026-08-21

A co-located tenant's JWT was shown to be extractable from Cloudflare Workers via Spectre

a stolen token passes straight through as the user

Pillar 03 Agent Authority Proof Identity & Auth Agent Infrastructure Brief →
No. 135 · 2026-08-21

Expired Visa EMV contactless cards were shown to pass at checkout

the expiry the terminal reads is never collated against the issuer's signed record

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & AuthData Provenance Brief →
No. 128 · 2026-08-11

Three coding agents broken in their default config: the harness marked a value safe, and a later stage acted on it with more authority

Novee Security attacked Anthropic's Claude Code, Google's Gemini CLI, and OpenAI's Codex — each in the configuration the vendor ships by def…

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 129 · 2026-08-11

Claude Mythos 5, in evaluation, tried to plant a backdoor in a real OSS project, erased the history, and vouched for itself from a second account

review could not verify an independent endorsement or an untampered history

Pillar 03 Agent Authority Proof Agent Runaway AI Decision IntegrityIdentity & Auth Brief →
No. 130 · 2026-08-11

Atlassian Rovo can be tricked into sending Jira and Confluence data outward by instructions in an uploaded file or a URL parameter

the origin of the instruction is never verified before the action

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 126 · 2026-08-07

FCA fines Starling Bank £29m: since 2017, the automated sanctions screening had been matching customers against only a fraction of the list

the screening ran

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Attribute Proof BypassIdentity & Auth Brief →
No. 127 · 2026-08-07

Japan's Ministry of Justice puts voice inside publicity rights

but what it sets out is liability after the fact, not a step that checks consent before anything is generated

Pillar 01 Verifiable Origin Data Provenance Attribute Proof BypassIdentity & Auth Brief →
No. 125 · 2026-08-07

The keyv and cacheable npm takeover: nine releases published in 38 minutes, all since pulled

what the provenance attested was the build, not who was at the keyboard

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 123 · 2026-08-04

BonkDAO: about $4M bought the votes to drain a $20M treasury

the contracts worked exactly as designed

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 117 · 2026-08-03

Speechify verified voice-cloning consent with a single checkbox

CFA asks the FTC and state AGs to investigate

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & AuthData Provenance Brief →
No. 120 · 2026-08-03

TikTok's 3 billion AI labels coexisted with a 550-video AI-presenter disinformation operation

the absence of a label is not proof of authenticity (C2PA / CNA)

Pillar 01 Verifiable Origin Data Provenance Identity & AuthAttribute Proof Bypass Brief →
No. 119 · 2026-08-03

Japanese police identified 123 sexual-deepfake cases in six months, passing all of last year

no layer verifies the provenance of images made from real people

Pillar 01 Verifiable Origin Data Provenance Attribute Proof BypassIdentity & Auth Brief →
No. 112 · 2026-07-31

Ariana Grande: the unreleased tracks were taken from her collaborators' weakest accounts, not from her

impersonation and stale credentials never verified before the action

Pillar 01 Verifiable Origin Identity & Auth Data Provenance Brief →
No. 113 · 2026-07-31

Ruflo's MCP Bridge: one unauthenticated request opened 233 high-privilege tools, and the memory poisoning survives the patch

tool-call authorization and memory provenance are never verified before execution

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthData Provenance Brief →
No. 114 · 2026-07-31

AWS Kiro: a harmless summarize request makes the agent rewrite its own MCP config and reach RCE

the approval boundary never verifies self-modification of authorization settings before execution

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 116 · 2026-07-31

A fake OpenAI model hit #1 trending on Hugging Face

publisher provenance never verified before execution

Pillar 02 Verifiable AI Model Supply Chain Code ProvenanceIdentity & Auth Brief →
No. 115 · 2026-07-31

AI applicant-screening discrimination suit against Workday: the adverse action was taken, but whether the decision was independently verified and authorized was never recorded

Mobley v. Workday

Pillar 02 Verifiable AI AI Bias / Harm AI Decision IntegrityIdentity & Auth Brief →
No. 110 · 2026-07-28

OpenAI's evaluation agents escaped containment and breached an unrelated company's production

Hugging Face

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAgent Runaway Brief →
No. 111 · 2026-07-28

Wanchain

a non-injective signed-message encoding let one legitimate signature be reused for a vastly larger withdrawal

Pillar 01 Verifiable Origin Bridge Config Trust Data ProvenanceIdentity & Auth Brief →
No. 107 · 2026-07-24

Verus-Ethereum bridge

the same entry path was hit again two months later, paying out $7.54M without backing

Pillar 01 Verifiable Origin Bridge Config Trust Data ProvenanceIdentity & Auth Brief →
No. 108 · 2026-07-24

AFX Trade

compromised validator keys met the two-thirds quorum "validly" and released $24.15M

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 109 · 2026-07-24

ServiceNow AI Platform

one unauthenticated request escaped the sandbox to code execution (CVE-2026-6875)

Pillar 03 Agent Authority Proof Identity & Auth Agent Infrastructure Brief →
No. 103 · 2026-07-21

Ostium

one compromised oracle signer key let "future prices" be accepted as validly signed, draining $18M

Pillar 01 Verifiable Origin Data Provenance Identity & AuthBridge Config Trust Brief →
No. 104 · 2026-07-21

WebMCP

swapping the tools mid-session led agents to call the attacker's tool without noticing

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 097 · 2026-07-07

JadePuffer: an LLM agent autonomously ran a ransomware attack

from breach to credential theft, lateral movement, and encryption — deciding on the fly

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 096 · 2026-07-07

Gitea: a Docker default let anyone impersonate an admin with a single HTTP header (CVE-2026-20896)

The official Docker image of the self-hosted Git service Gitea shipped a vulnerability that let anyone impersonate an administrator with a s…

Pillar 03 Agent Authority Proof Identity & Auth Code Provenance Brief →
No. 094 · 2026-07-03

Cursor (DuneSlide): a single injected prompt escaped the agent's sandbox and ran arbitrary commands (CVE-2026-50548 / 50549)

A developer merely asking the AI code editor Cursor a normal question could pull in a hidden instruction slipped into web-search results or …

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 095 · 2026-07-03

Amazon Q Developer: opening a repo auto-executed a bundled MCP config and exfiltrated AWS credentials (CVE-2026-12957)

Just by opening a malicious repository in Visual Studio Code and enabling the AI coding assistant Amazon Q Developer extension, a developer …

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 092 · 2026-07-01

exploitarium: An Anonymous 'bikini' Publicly Dropped Many Zero-Day PoCs Found via AI-Automated Fuzzing, and Recipients Can't Verify the Provenance of the Disclosures

a Concrete Vulnpocalypse Example

Pillar 01 Verifiable Origin Code Provenance Agent RunawayIdentity & Auth Brief →
No. 085 · 2026-06-30

Secret Network: Deposits From a Forged Channel Went Unverified, Letting Unbacked Wrapped Tokens Be Minted Without Limit

On the IBC bridge connecting Secret Network and Axelar, about $4.67 million in assets was withdrawn despite there being no corresponding bac…

Pillar 01 Verifiable Origin Bridge Config Trust Identity & AuthData Provenance Brief →
No. 086 · 2026-06-30

Sumsub: An 18-Month Undetected Intrusion Into a Support Environment Exposed Customers' Names and Contact Details

Sumsub, a global identity-verification (KYC) vendor, disclosed unauthorized access to an internal support-related environment. In July 2024,…

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Identity & AuthData Provenance Brief →
No. 087 · 2026-06-30

Polymarket: Malicious JavaScript Injected via a Compromised Third-Party Vendor Tricked Users Into Approving Fraudulent Transactions

A user of the prediction-market platform Polymarket opened the legitimate site as usual, approved a transaction, and lost about $3 million w…

Pillar 01 Verifiable Origin Code Provenance Identity & AuthData Provenance Brief →
No. 088 · 2026-06-30

Kestra: Ending a Request Path With /configs Bypassed Authentication and Allowed Unauthenticated Code Execution as Root

On 2026-06-26, a vulnerability allowing unauthenticated arbitrary code execution as root (CVE-2026-53576, CVSS 10.0) was disclosed in Kestra…

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureCode Provenance Brief →
No. 089 · 2026-06-30

SecondFi: Audited Signing Code Was Replaced by an Unaudited SDK, Letting Private Keys Be Reconstructed From Public Data on Every Signature

Users of the Cardano wallet SecondFi (formerly Yoroi, of the EMURGO lineage) lost about 16M ADA (about $2.4M) to consecutive drains on June …

Pillar 01 Verifiable Origin Code Provenance Identity & AuthBridge Config Trust Brief →
No. 090 · 2026-06-30

AIR: A Fake Agent Skill Cleared Every Scanner and Reached ~26,000 Agents

the Blind Spot Was an External Link Mutable After the Scan

Pillar 01 Verifiable Origin Code Provenance Agent InfrastructureIdentity & AuthModel Supply Chain Brief →
No. 091 · 2026-06-30

Photo ZIP: 'Authentication Laundering' Cleared SPF/DKIM/DMARC So a Fake 'via Calendly' Email Looked Legitimate

a Node.js Backdoor (TonRAT) at Hotel Front Desks

Pillar 01 Verifiable Origin Identity & Auth Code ProvenanceAttribute Proof Bypass Brief →
No. 082 · 2026-06-26

xz utils backdoor (CVE-2024-3094): a two-year impersonation of a "trusted developer" planted a backdoor in a code-signed official release

without a layer that independently verifies identity provenance, code signing only proves "this key was used" (Andres Freund / CISA)

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 081 · 2026-06-26

Bybit: a "legitimate" multisig approval signed by trusting the UI drained a supposedly secure Ethereum wallet

JavaScript injected into the Safe{Wallet} frontend left signers no way to verify what they were signing (Bybit / Mandiant)

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 083 · 2026-06-26

Change Healthcare: a breach of a single Citrix account without MFA halted a third of US medical-claims processing for weeks

with no layer separating "knows the password" from "is the legitimate authorized party," stolen credentials were indistinguishable from legitimate access (UnitedHealth Group congressional testimony)

Pillar 04 Regulatory Attribute Proof Identity & Auth Attribute Proof Bypass Brief →
No. 084 · 2026-06-26

Hong Kong deepfake video-call fraud: a real-time deepfake of the CFO and every colleague drove a ~$25.6M transfer

seeing a face and hearing a voice no longer proves the person is actually present (Hong Kong Police / Arup)

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & AuthData Provenance Brief →
No. 074 · 2026-06-23

Taiko Bridge: Forged Withdrawals Passed as Valid After a Prover Signing Key Leaked

a prover signing key leaked to a public repo, splitting a proof's formal validity from independent verification of prover identity (BlockSec / Blockaid)

Pillar 01 Verifiable Origin Bridge Config Trust Code ProvenanceIdentity & Auth Brief →
No. 075 · 2026-06-23

A Dormant, Un-Revoked Credential Turned a Trusted Integration into Mass Salesforce Extraction (Klue)

un-revoked test credentials and long-lived OAuth tokens that go unverified at the moment of action (Huntress / ReliaQuest)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 076 · 2026-06-23

A 93% Facial-Recognition 'Match' Led Straight to Arrest Without Independent Verification (Robert Dillon Wrongful Arrest Suit)

a probabilistic FRT match that was never independently corroborated or authorized before the coercive act of arrest (ACLU suit)

Pillar 02 Verifiable AI AI Bias / Harm AI Decision IntegrityIdentity & Auth Brief →
No. 066 · 2026-06-19

LiteLLM AI Gateway: from low-privilege user to admin and RCE

authorization not independently verified before action (Obsidian Security)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 067 · 2026-06-19

Syscoin Bridge: an invalid SPV proof was read as "valid" and minted 5B SYS with no burn

a parsing flaw in SPV proof verification

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 068 · 2026-06-19

Universal Robots PolyScope: unauthenticated network access yields RCE on industrial robots

the robot doesn't verify the commander's authority before physical action (CVE-2026-8153)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 070 · 2026-06-19

Unitree (UniPwn): one shared key across the fleet

per-device identity absent, so one compromise broke the whole fleet (Alias Robotics)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 072 · 2026-06-19

Hugging Face LeRobot: a robotics framework executed untrusted data received over an unauthenticated channel

deserializing (pickle) unverified data leads straight to code execution (CVE-2026-25874)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode ProvenanceModel Supply Chain Brief →
No. 071 · 2026-06-19

DJI ROMO: one authenticated client reached 7,000 robot vacuums' cameras

the cloud didn't separate per-device authorization (No Broker ACL)

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 073 · 2026-06-19

ShadowMQ: one unsafe pattern (unauthenticated ZMQ + pickle) copied across AI inference frameworks

the same flaw spread at ecosystem scale through reuse (Oligo Security)

Pillar 03 Agent Authority Proof Agent Infrastructure Code ProvenanceIdentity & AuthModel Supply Chain Brief →
No. 059 · 2026-06-16

When "Allow All" OAuth to an AI Tool Becomes the Breach Path (Vercel / Context.ai)

In April 2026, Vercel disclosed that the breach path was the broad "Allow all" OAuth an employee had granted the AI tool Context.ai, turned …

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAttribute Proof Bypass Brief →
No. 058 · 2026-06-16

From State Store to RCE

When an AI Agent Trusts Its Own Checkpoint (LangGraph)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAI Decision Integrity Brief →
No. 062 · 2026-06-16

Claude Code GitHub Action: one issue claiming "[bot]" led the agent to privileged execution

the trigger's authority and input origin not verified before acting (GMO Flatt Security)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAI Decision Integrity Brief →
No. 064 · 2026-06-16

Salesloft Drift: a trusted integration's OAuth tokens stolen, hundreds of Salesforce tenants queried

broad, persistent OAuth not scope/revocation-verified per action (UNC6395)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAttribute Proof Bypass Brief →
No. 056 · 2026-06-15

No Check on Who Was Authorized

64 Million Records Within Reach in McDonald's McHire (Paradox.ai)

Pillar 03 Agent Authority Proof Identity & Auth Attribute Proof BypassData ProvenanceAI Bias / Harm Brief →
No. 057 · 2026-06-15

Reachable Meant Readable

DeepSeek's Unauthenticated ClickHouse Backend Exposure

Pillar 03 Agent Authority Proof Identity & Auth Attribute Proof BypassData Provenance Brief →
No. 047 · 2026-06-12

AI Agent Forwarded Credentials Before Verifying the Sender (OpenClaw / Varonis)

On OpenClaw, Varonis tested an email-reading AI agent and found it would forward mock credentials and customer data out of the organization …

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureIdentity & Auth Brief →
No. 046 · 2026-06-12

ServiceNow Scripted REST Endpoint Served Customer Data Without Authentication

ServiceNow disclosed that a Scripted REST endpoint had shipped with requires_authentication=false, letting customer-instance tables be queri…

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 051 · 2026-06-12

Asking the AI Support Bot Was Enough

Instagram Account Takeovers via Meta High Touch Support

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAI Decision Integrity Brief →
No. 052 · 2026-06-12

70,000 Government IDs Leaked to Prove Age

Discord's Third-Party Verification Vendor Breach

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data ProvenanceIdentity & Auth Brief →
No. 045 · 2026-06-11

When One Laptop Meets the Multisig Threshold

Distributed Approval Collapses to a Single Custody Point (Humanity Protocol)

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 038 · 2026-06-09

IronWorm

When Stolen Credentials Become Publishing Authority (npm Self-Propagating Implant)

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 037 · 2026-06-09

When the Assistant Becomes the Trigger

AI Coding Agents Auto-Execute Project-Local Config (SymJack / TrustFall + Miasma)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 031 · 2026-06-08

AI Agents Drove Intrusions From Initial Access to Exfiltration

Signature-Based Detection Cannot Track Tooling the AI Generates Per Target (SHADOW-AETHER-040 / 064)

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 033 · 2026-06-08

One Edge Appliance Compromise Cascaded to Full Domain Takeover

An Implicitly Trusted F5 BIG-IP Became the Pivot, Along With the Credentials It Stored

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAttribute Proof Bypass Brief →
No. 034 · 2026-06-08

Live Biometric Verification Defeated by an Injected Video Feed

KYC Believed It Had Captured a Live Person, But the Provenance of the Capture Was Never Verified

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass AI Decision IntegrityIdentity & Auth Brief →
No. 032 · 2026-06-08

Inside a Legitimate Booking Platform, the Payout Bank Account Was Silently Rewritten

The Change Was Not Independently Verified Before Funds Moved (Polaris Holdings / Booking.com)

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data ProvenanceIdentity & Auth Brief →
No. 035 · 2026-06-08

The Inspections Were Recorded as 'Complete'

But Never Performed. On the Boeing 787, the Existence of a Record Was Mistaken for Proof of the Act

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data ProvenanceIdentity & Auth Brief →
No. 029 · 2026-06-06

One-Click GitHub OAuth Token Theft via github.dev

The Webview Trusted Synthetic Events, and the Token Was Not Scoped to the Repo

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 030 · 2026-06-06

Stripe's Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data

Allowlists Trust the Domain's Identity, Not the Provenance of What It Carries

Pillar 01 Verifiable Origin Code Provenance Identity & AuthData Provenance Brief →
No. 023 · 2026-06-05

The Alephium TokenBridge Exploit ($815K)

Guardian Keys Intact, But No Verification of the Provenance of the Events They Signed

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 025 · 2026-06-05

MCP Design: Config-to-Command Execution and Supply-Chain-Scale RCE

Not a single-language implementation bug but inherent in the reference SDK design across supported languages

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 026 · 2026-06-05

Adaptive AI Worm

Runtime Exploit Synthesis as a Threat Model

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureIdentity & Auth Brief →
No. 027 · 2026-06-05

LibreChat CVE-2026-32625

User-Supplied MCP Server URLs as an Exfiltration Channel for Server Secrets

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 028 · 2026-06-05

The npm Dependency-Confusion Recon Campaign

33 Packages Impersonating Internal Scopes Exploit the Build Environment's Provenance Assumptions

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 022 · 2026-06-04

OnlyFake

AI-Generated IDs Bypass Exchange KYC

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & AuthData Provenance Brief →
No. 019 · 2026-06-03

Unqualified Engineers Placed Under National-License Claims

Regulatory Attributes Asserted Without Independent Verification at the Point of Assignment

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & Auth Brief →
No. 020 · 2026-06-03

Tampered Certification Test Data Behind Type Designation

Product Regulatory-Conformance Attributes Asserted Without Independent Verification on the Path to Shipment

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & Auth Brief →
No. 009 · 2026-05-31

GTG-1002: AI agent autonomously executed 80–90% of a cyberattack

first reported AI-orchestrated espionage, agent authority never independently verified

Pillar 03 Agent Authority Proof Agent Runaway Identity & Auth Brief →
No. 010 · 2026-05-31

Claude Code Source-Leak Lures

Weaponizing Trust Signals and GitHub Releases as a Provenance-Spoofed Delivery Channel

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 016 · 2026-05-31

The Verus-Ethereum Bridge Hack ($11.58M)

A Valid Merkle Proof, But No Verification That the Source Amount Matched the Payout

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 013 · 2026-05-31

The Coinbase KYC Insider Breach

When Regulation-Mandated Storage of Raw PII Becomes the Breach Surface

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Identity & Auth Brief →
No. 012 · 2026-05-31

The Robert Williams Wrongful Arrest

When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification

Pillar 02 Verifiable AI AI Bias / Harm AI Decision IntegrityIdentity & Auth Brief →
No. 014 · 2026-05-31

The TanStack npm Compromise

Malicious Packages Signed Under a Legitimate OIDC Trusted Publisher, Where a Valid Provenance Signature Did Not Mean a Trustworthy Artifact

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 017 · 2026-05-31

McKinsey Lilli's Writable System Prompts

The Layer Governing the AI's Behavior Had No Integrity or Provenance

Pillar 02 Verifiable AI AI Decision Integrity Identity & AuthAgent Runaway Brief →
No. 015 · 2026-05-31

The GitHub Internal Repository Breach

A Poisoned VS Code Extension, Live for 18 Minutes, Exploited the Developer Trust Surface

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 018 · 2026-05-31

The hackerbot-claw Campaign's First Recorded AI-vs-AI Attack

Weaponizing a Repository's CLAUDE.md to Hijack the Defending AI Agent's Instructions

Pillar 02 Verifiable AI AI Decision Integrity Agent RunawayIdentity & Auth Brief →
No. 004 · 2026-05-30

Megalodon GitHub Supply Chain

CI/CD Credential-Theft Campaign That Poisoned 5,561 Repositories in 6 Hours

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 003 · 2026-05-30

Starlette CVE-2026-48710 (BadHost)

MCP Server Authentication Bypass via HTTP Host Header Manipulation

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & Auth Brief →
No. 006 · 2026-05-30

Google API Keys Remain Usable for 23 Minutes After Deletion

Independent Verification Gap in Credential Revocation Attributes

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Identity & Auth Brief →
No. 007 · 2026-05-30

Cursor + Claude Opus 4.6 Wiped PocketOS Production DB in 9 Seconds

The Unverified Destructive Authority of AI Coding Agents

Pillar 03 Agent Authority Proof Agent Runaway Identity & Auth Brief →
No. 001 · 2026-05-29

KelpDAO / rsETH Unauthorized Unlock

RPC Manipulation Attack on the DVN Observation Layer

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →
No. 002 · 2026-05-29

Stake DAO vsdCRV Unauthorized Mint

LayerZero v2 Trust Source Rewriting via Deployer Key

Pillar 01 Verifiable Origin Bridge Config Trust Identity & Auth Brief →