Pillar 01 Verifiable Origin
The layer that independently verifies the origin of messages, data, and code.
The keyv and cacheable npm takeover: nine releases published in 38 minutes, all since pulled
what the provenance attested was the build, not who was at the keyboard
Japan's Ministry of Justice puts voice inside publicity rights
but what it sets out is liability after the fact, not a step that checks consent before anything is generated
7.6 petabytes of Hugging Face training data held 221,303 live secrets
detected and notified, never revoked (Truffle Security)
BonkDAO: about $4M bought the votes to drain a $20M treasury
the contracts worked exactly as designed
A Copilot for Word document worm turned each generated file into the next carrier
recipients cannot verify the edited document reflects the source data
Japanese police identified 123 sexual-deepfake cases in six months, passing all of last year
no layer verifies the provenance of images made from real people
TikTok's 3 billion AI labels coexisted with a 550-video AI-presenter disinformation operation
the absence of a label is not proof of authenticity (C2PA / CNA)
Ariana Grande: the unreleased tracks were taken from her collaborators' weakest accounts, not from her
impersonation and stale credentials never verified before the action
Wanchain
a non-injective signed-message encoding let one legitimate signature be reused for a vastly larger withdrawal
Verus-Ethereum bridge
the same entry path was hit again two months later, paying out $7.54M without backing
AFX Trade
compromised validator keys met the two-thirds quorum "validly" and released $24.15M
Ostium
one compromised oracle signer key let "future prices" be accepted as validly signed, draining $18M
Figma
AI content training defaulted on for individuals and small teams, and off for enterprise
Over 40,000 unauthorized likeness and voice posts across major platforms
and a 100% takedown rate did not stop the same person's models from reappearing (JAPRO FY2025 survey)
Friendly Fire
a defensive AI coding agent ran the very binary it was asked to vet
Paysafe fake SDKs: 17 packages posing as legitimate payment SDKs exfiltrated developers' secrets, payment API keys and all
The supply-chain security firm Socket detected 17 malicious packages (13 on npm, 4 on PyPI) that pose as SDKs for the payment services Paysa…
Aptos: a Move VM type confusion could let one on-chain resource be treated as another (reproduced in a ~$3,000 test environment)
The blockchain security firm Hexens disclosed a critical vulnerability in Aptos's Move VM (the execution environment that processes every sm…
exploitarium: An Anonymous 'bikini' Publicly Dropped Many Zero-Day PoCs Found via AI-Automated Fuzzing, and Recipients Can't Verify the Provenance of the Disclosures
a Concrete Vulnpocalypse Example
Secret Network: Deposits From a Forged Channel Went Unverified, Letting Unbacked Wrapped Tokens Be Minted Without Limit
On the IBC bridge connecting Secret Network and Axelar, about $4.67 million in assets was withdrawn despite there being no corresponding bac…
Polymarket: Malicious JavaScript Injected via a Compromised Third-Party Vendor Tricked Users Into Approving Fraudulent Transactions
A user of the prediction-market platform Polymarket opened the legitimate site as usual, approved a transaction, and lost about $3 million w…
SecondFi: Audited Signing Code Was Replaced by an Unaudited SDK, Letting Private Keys Be Reconstructed From Public Data on Every Signature
Users of the Cardano wallet SecondFi (formerly Yoroi, of the EMURGO lineage) lost about 16M ADA (about $2.4M) to consecutive drains on June …
AIR: A Fake Agent Skill Cleared Every Scanner and Reached ~26,000 Agents
the Blind Spot Was an External Link Mutable After the Scan
Photo ZIP: 'Authentication Laundering' Cleared SPF/DKIM/DMARC So a Fake 'via Calendly' Email Looked Legitimate
a Node.js Backdoor (TonRAT) at Hotel Front Desks
Bybit: a "legitimate" multisig approval signed by trusting the UI drained a supposedly secure Ethereum wallet
JavaScript injected into the Safe{Wallet} frontend left signers no way to verify what they were signing (Bybit / Mandiant)
xz utils backdoor (CVE-2024-3094): a two-year impersonation of a "trusted developer" planted a backdoor in a code-signed official release
without a layer that independently verifies identity provenance, code signing only proves "this key was used" (Andres Freund / CISA)
Taiko Bridge: Forged Withdrawals Passed as Valid After a Prover Signing Key Leaked
a prover signing key leaked to a public repo, splitting a proof's formal validity from independent verification of prover identity (BlockSec / Blockaid)
Common Crawl: about 12,000 live credentials embedded in a public corpus used to train LLMs
training-data provenance not verified before ingestion (Truffle Security)
Syscoin Bridge: an invalid SPV proof was read as "valid" and minted 5B SYS with no burn
a parsing flaw in SPV proof verification
Bright Data SDK: your living-room TV became a relay node for AI-scraping
the origin and consent of collected data and relayed traffic not independently verified (Include Security)
Generated Until the Rightsholder Said No
The Consent-and-Provenance Gap Behind OpenAI Sora 2
TrapDoor Plants Hidden Directives in AI Assistant Instruction Files Across npm, PyPI, and Crates.io
TrapDoor, disclosed by Socket, is a credential-stealing campaign whose distinctive technique plants invisible directives via zero-width Unic…
200 Million Views of Fake Celebrities
The Likeness Provenance Gap Behind YouTube's Deepfake Detection
When One Laptop Meets the Multisig Threshold
Distributed Approval Collapses to a Single Custody Point (Humanity Protocol)
IronWorm
When Stolen Credentials Become Publishing Authority (npm Self-Propagating Implant)
12.8 Billion Training Images Contained Passports, Résumés, and Faces
The Provenance and Consent of Training Data Were Never Verified at Collection
Stripe's Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data
Allowlists Trust the Domain's Identity, Not the Provenance of What It Carries
The Alephium TokenBridge Exploit ($815K)
Guardian Keys Intact, But No Verification of the Provenance of the Events They Signed
The npm Dependency-Confusion Recon Campaign
33 Packages Impersonating Internal Scopes Exploit the Build Environment's Provenance Assumptions
Claude Code Source-Leak Lures
Weaponizing Trust Signals and GitHub Releases as a Provenance-Spoofed Delivery Channel
SynthID Watermark, Statistically Stripped
a provenance mark that can be removed and forged (Google DeepMind / Alosh Denny)
The GitHub Internal Repository Breach
A Poisoned VS Code Extension, Live for 18 Minutes, Exploited the Developer Trust Surface
The Verus-Ethereum Bridge Hack ($11.58M)
A Valid Merkle Proof, But No Verification That the Source Amount Matched the Payout
The TanStack npm Compromise
Malicious Packages Signed Under a Legitimate OIDC Trusted Publisher, Where a Valid Provenance Signature Did Not Mean a Trustworthy Artifact
Megalodon GitHub Supply Chain
CI/CD Credential-Theft Campaign That Poisoned 5,561 Repositories in 6 Hours
Discord 2.05 Billion Message Scraping via Public API
How Public Channel Data Gets Redistributed as AI Training Datasets
KelpDAO / rsETH Unauthorized Unlock
RPC Manipulation Attack on the DVN Observation Layer
Stake DAO vsdCRV Unauthorized Mint
LayerZero v2 Trust Source Rewriting via Deployer Key