Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Category archive
Lemma Critical Brief · Category archive

KYC / AML Disclosure

PII over-disclosure, KYC-anchored leaks, custody-chain regulatory violations.

9 Briefs
No. 149 · 2026-09-21

Revolut: It kept handing over customer data for months, answering disclosure requests that arrived through Italy's state-certified email network (PEC; Italian prosecutors investigating)

the state certifies delivery, but nothing verifies the requester's authority before the data goes out

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Attribute Proof BypassIdentity & Auth Brief →
No. 141 · 2026-09-04

IDScan.net: More than 153 million scanned driver's licenses handed over at counters were being sold on the dark web

the check ends in a moment, the image does not

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass KYC / AML DisclosureData Provenance Brief →
No. 126 · 2026-08-07

FCA fines Starling Bank £29m: since 2017, the automated sanctions screening had been matching customers against only a fraction of the list

the screening ran

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Attribute Proof BypassIdentity & Auth Brief →
No. 101 · 2026-07-10

Paysafe fake SDKs: 17 packages posing as legitimate payment SDKs exfiltrated developers' secrets, payment API keys and all

The supply-chain security firm Socket detected 17 malicious packages (13 on npm, 4 on PyPI) that pose as SDKs for the payment services Paysa…

Pillar 01 Verifiable Origin Code Provenance KYC / AML DisclosureAttribute Proof Bypass Brief →
No. 093 · 2026-07-03

A7A5: a ruble-backed stablecoin moved $110B under sanctions

fully traceable on-chain, yet nothing proves or blocks a sender's sanctions status at transaction time (CertiK / Elliptic)

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Attribute Proof BypassData Provenance Brief →
No. 086 · 2026-06-30

Sumsub: An 18-Month Undetected Intrusion Into a Support Environment Exposed Customers' Names and Contact Details

Sumsub, a global identity-verification (KYC) vendor, disclosed unauthorized access to an internal support-related environment. In July 2024,…

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Identity & AuthData Provenance Brief →
No. 077 · 2026-06-23

IDMerit: the disputed billion-record KYC exposure

an unsecured database was found, but no one can prove whose data it was (Cybernews report, IDMerit denial)

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Data ProvenanceAttribute Proof Bypass Brief →
No. 021 · 2026-06-03

Wirecard: forged bank balance confirmations asserted €1.9B that didn't exist

a financial attribute disclosed without independent verification

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass KYC / AML Disclosure Brief →
No. 013 · 2026-05-31

The Coinbase KYC Insider Breach

When Regulation-Mandated Storage of Raw PII Becomes the Breach Surface

Pillar 04 Regulatory Attribute Proof KYC / AML Disclosure Identity & Auth Brief →