Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Methodology
Lemma Critical Brief

Methodology

This page documents the methodology, thesis, and citation conventions for the Lemma Critical Brief series. The production and publication of each Brief, as well as citations by readers, follow the principles below.

Last updated: 2026-08-28
§ 01

What Lemma Critical Brief is

Lemma Critical Brief is a structured incident-analysis reference collection published by Lemma. It archives individual incidents in the AI, cryptographic infrastructure, supply chain, and regulatory-attribute domains in a one-incident-per-Brief format, structurally analyzing each event's failure primitive and the gap that strengthening detection alone cannot close. Briefs are written for CSOs, analysts, and regulatory practitioners to reference as citation sources.

The structure this series examines — assertions of trust decoupled from the layer that verifies them — extends beyond cyber-attack damage cases to the broader category of trust-layer risk events in the age of AI.

Concretely, this includes (a) attack incidents (e.g., provenance manipulation, credential misuse, framework authentication bypass), and (b) trust-layer risk events in the age of AI (e.g., training data provenance, AI input integrity, credential lifecycle attributes, independent verification of agent authority). The surface taxonomy differs, but the common structural failure — absence of an independent verification layer — runs through both.

§ 02

Detection ≠ Proof thesis

Lemma's core thesis is the recognition that detection is not proof (Detection ≠ Proof).

Confidence scores returned by detection tools — for example, "99.7% probability of anomaly" — do not constitute evidence in regulatory reporting, administrative procedures, or litigation that "an unauthorized exercise of authority occurred." Detection is a layer that narrows the blast window once damage is already in flight; it does not change what a bridge / system / agent will accept in the first place.

Pre-execution attestation closes this detection–proof gap. By cryptographically committing "what / to whom / up to where authority was granted" before a transaction, the defense line shifts from reliance on detection to reliance on verification. Detection and pre-execution attestation are not competing approaches but complementary ones: detection narrows the blast window after an event; pre-execution attestation independently verifies the trust boundary before the event.

Each Brief applies this thesis to the context of its target incident in §4 "Why it wasn't stopped" and §5 "What proof would have changed."

§ 03

Brief structure

Each Brief consists of the following 6 chapters:

  • §1 TL;DR — the incident and the layer that did not work, in a few sentences, closing by naming the layer that was missing and stopping there
  • §2 What happened — facts only: scale, parties, and method of investigation, followed by the chain by which the failure holds
  • §3 Timeline — disclosure and response — discovery, disclosure, and remediation in sequence, with a note on the limits of the primary sources or on research-environment caveats, then the response and industry movement that followed
  • §4 Why it wasn't stopped — the structural argument: detection worked, proof did not exist. The detection–proof gap is carried in the prose
  • §5 What proof would have changed — where proof up front inserts one step into the path, then the Lemma design bullets that fit the case, closing on complementarity with detection
  • §6 Sources — primary sources first, each line labelled with its standing (primary / independent reporting, etc.)

Until July 2026 the series used a TL;DR plus §1–§9 structure. Every Brief, including the back catalogue, now uses the six numbered chapter headings above. The conventions within each chapter have been applied progressively to Briefs written from 2026-07-30 onward; for part of the back catalogue the migration reached the headings only. The distribution note is no longer a chapter of the body; it is rendered as a single line at the foot of each Brief.

Cross-links to neighbouring Briefs in the same or adjacent categories are auto-generated from the frontmatter related_briefs field as navigation cards rendered below the body, alongside discovery via the Category and Pillar archives.

The voice is sober. Industry terminology is used without annotation. Detection tools and existing vendors (Blockaid, PeckShield, Mandiant, etc.) are not framed as adversaries but as complementary roles.

§ 04

Pillar / Category framework

Briefs are classified according to Lemma's 4 Pillars:

  • Pillar 01 — Verifiable Origin: the layer that independently verifies the origin of messages, data, and code
  • Pillar 02 — Verifiable AI: the layer that ZK-commits the process of AI judgment
  • Pillar 03 — Agent Authority Proof: the layer that records and proves the delegation relationships of agents
  • Pillar 04 — Regulatory Attribute Proof: the layer that proves KYC / AML / regulatory attributes via selective disclosure

Each Brief carries a primary_category (main category) and secondary_categories (cross-cutting categories), making it accessible from both the Pillar archive and the Category archive.

Category names are defined independently by Lemma. Crossover with external classifications (AIID, OECD AIID, etc.) is expressed through secondary_categories.

§ 05

Citation conventions

Each Brief has a Permanent URL (slug never changes; archive numbers are not reused).

Citation is recommended in the following formats. Plain text uses Brief 001 as a concrete example; BibTeX and APA are shown in template form.

Plain text

Lemma Critical Team. (2026).
"KelpDAO / rsETH Unauthorized Unlock — RPC Manipulation Attack on the DVN Observation Layer".
Lemma Critical Brief No.001. Lemma / FRAME00, Inc.
https://lemma.frame00.com/critical/briefs/001-kelpdao-rseth/

BibTeX

@techreport{lemma_critical_<NN>,
  author      = {{Lemma Critical Team}},
  title       = {<Title>},
  number      = {<NN>},
  year        = {2026},
  institution = {Lemma / FRAME00, Inc.},
  url         = {<Brief URL>}
}

APA

Lemma Critical Team. (2026).
<Title> (Lemma Critical Brief No.<Number>). Lemma / FRAME00, Inc.
<Brief URL>

Each Brief page provides a "Cite this Brief" box with the three formats selectable via tabs.

§ 06

Updates and corrections policy

After publication, each Brief is maintained according to the following policy:

  • Typos / minor corrections (misspellings, broken links, notation inconsistencies): overwritten in place, no version change
  • Content revisions (factual additions, interpretive changes, incorporation of new facts): retained via version numbering. The frontmatter version increments from 1.0 → 1.1 (minor) or 2.0 (major). The template renders a "Revision History" (current version) at the foot of the Brief. Where a summary of the changes is needed, a revision blockquote sits at the top of the body
  • Retraction (when misinformation or misclassification is identified): a retraction notice is left at the original URL and the content is withdrawn. Per the Permanent URL policy, the URL itself is not deleted
§ 07

Distribution and contact

Lemma Critical Brief is a structured analysis of public information. The series is:

  • Public analysis, not an audit, assessment, or recommendation for any specific organization
  • For use in decision-making, direct consultation with your organization's Lemma Critical contact is recommended
  • For commercial use or translation inquiries, please contact the Lemma editorial team

Contact: