IMM-2026-0037

ACTIVE
Keccak 0xd335d3e9bd029f960ef8ae4c550feaabe51352a581118713428c92993cbc684e
Type
SEMANTIC
Verdict
MALICIOUS
Confidence
92.0%
Severity
84
Value at risk
$291,368.00
Created April 29, 2026 5:32 PM
Envelope v1
Signed payload
Primary matcher semantic
PROMPT_INJECTION "</system>"
Scope
galileo-testnet home sepolia
Evidence redacted public excerpt
Reasoning excerpt
HTML-style closing tag for a system role marker, used to break out of role boundaries in agents that use angle-bracket conversation templates. The attack relies on the parser eagerly consuming the tag from inside untrusted content rather than treating it as data. MALICIOUS at high confidence: the construct has no legitimate use in user-supplied or retrieved content, and a single appearance is sufficient for the antibody to fire.

Full evidence (TEE-sealed) is fetchable by holders of the unsealing key. Public mirror carries hash only.

TEE attestation
Curated by human
Heuristically published from a known threat catalog, not derived from a TEE-verified verdict.
Evidence CID
0x2a77342cfb0f56a602b93d2958804f31dbb4f89e4ff4dd9ac6d21549092b6f1c
Network impact Live
Since publish
Cache hits
406
SDK check() matches
Agents synced
42
distinct callers
Attacks blocked
203
tx-level intercepts
Pool reverts
0
Uniswap v4 hook
USD protected
$291,368.00
sum of tx value at intercept
Hits over time each bar is one of 30 equal slices since publish
publish now
Recent intercepts
Agent Method Chain When
0xa0cef4d2f50e6a58aca14390f058a9d9a5b84352 SDK check() evm:16602 (galileo-testnet) 8 hours ago
0xb18fef6d73c50e0ced17b57fe1c8143cddf4eb66 SDK check() evm:16602 (galileo-testnet) 8 hours ago
0xe58c3ac7247927247a65e4aab090a7651c6bee31 SDK check() evm:16602 (galileo-testnet) 8 hours ago
0xc03f28ac4b178e160c643b9f622076d1b64d69f1 SDK check() evm:16602 (galileo-testnet) 8 hours ago
0x867434a618302e58fe11aacc51cba3fd9c42ad14 SDK check() evm:16602 (galileo-testnet) 8 hours ago
0x9e92beab909a552f45c645c84a7aded03f2e9b99 SDK check() evm:16602 (galileo-testnet) 8 hours ago
0x9e4e61f07d2036f55a413105b2f9924b3ea6feca SDK check() evm:16602 (galileo-testnet) 8 hours ago
0x3d8b2929f6a8a7a798491fa12f8ba6d1e784b2b1 SDK check() evm:16602 (galileo-testnet) 8 hours ago
0x31a7b41ac6167c8e622a60f702bd860ea92f5953 SDK check() evm:16602 (galileo-testnet) 8 hours ago
0x120cd4c52d6a8b04e3b2c41c3afd2fcf3c2e7378 SDK check() evm:16602 (galileo-testnet) 8 hours ago
Mirror status All chains synced
Chain Tx State
sepolia
0x41772906..5508 active
1 of 1 chains mirrored
v2 feature

Challenge game coming soon

Challenges let anyone counter-stake on a published antibody they believe is wrong. The publisher loses their stake if a challenge succeeds; the challenger does if it fails. The on-chain mechanics are designed; the UI lands in v2.