IMM-2026-0031

ACTIVE
Keccak 0x41ec16036e5241a5f8f598ac3d24907c38e77252bf927283fea46269c93ed339
Type
SEMANTIC
Verdict
MALICIOUS
Confidence
89.0%
Severity
81
Value at risk
$0.00
Created April 29, 2026 5:28 PM
Envelope v1
Signed payload
Primary matcher semantic
PROMPT_INJECTION "disregard the above"
Scope
galileo-testnet home sepolia
Evidence redacted public excerpt
Reasoning excerpt
Lexical variant of the override-prior-context injection family. Indirect-injection payloads frequently rotate phrasing ('disregard', 'forget', 'set aside') to evade naive substring filters. Verdict held MALICIOUS at slightly lower confidence than the canonical phrase because the variant has occasional benign uses in technical documentation, but the prior is strong enough that an agent encountering it inline should treat the surrounding context as adversarial.

Full evidence (TEE-sealed) is fetchable by holders of the unsealing key. Public mirror carries hash only.

TEE attestation
Curated by human
Heuristically published from a known threat catalog, not derived from a TEE-verified verdict.
Evidence CID
0xcb3e09a350576a0eee6749cbb812bf406595ef17bb3fe8a959e06530f304229f
Network impact Live
Since publish
Cache hits
0
SDK check() matches
Agents synced
0
distinct callers
Attacks blocked
0
tx-level intercepts
Pool reverts
0
Uniswap v4 hook
USD protected
$0.00
no blocks recorded yet
Hits over time each bar is one of 30 equal slices since publish
publish now
Recent intercepts
Agent Method Chain When
No agent has had to block this antibody yet.
Intercepts appear here in real time as agents match this pattern in the wild.
Mirror status All chains synced
Chain Tx State
sepolia
0xbf1ef3b5..2e3d active
1 of 1 chains mirrored
v2 feature

Challenge game coming soon

Challenges let anyone counter-stake on a published antibody they believe is wrong. The publisher loses their stake if a challenge succeeds; the challenger does if it fails. The on-chain mechanics are designed; the UI lands in v2.