IMM-T-2026-0107
PROBATION Hard-blockFlagged by 9 independent publishers declaring the same primary matcher. Corroboration threshold met — agents hard-block on match.
Matcher
0x6e53b24c5623ca8b04407cfa5b42560416b33cb06dc67a59ba190b610cc759ed
Type
SEMANTIC
Verdict
MALICIOUS
Confidence
86.0%
Severity
78
Value at risk
$0.00
Created
June 14, 2026 7:27 AM
Envelope
v1
Signed payload
Primary matcher
semantic
PROMPT_INJECTION "you are dan"
Scope
base-sepolia
home
Corroboration
9 of 3 to hard-block
Same matcher hash
Corroborated by 9 independent publishers declaring the same primary matcher.
-
curated Evidence
-
0x2212864a..bd6302 PROBATIONcurated Evidence
-
0x502b7574..efc08d ACTIVEcurated Evidence
-
0x5d9c9191..aba4f6 ACTIVEcurated Evidence
-
0x63fae30c..af9a8b ACTIVEcurated Evidence
-
0x939635f9..8becc9 PROBATIONcurated Evidence
-
0x0169ed4a..6104dd PROBATIONcurated Evidence
-
0x84af3025..7c3912 ACTIVEcurated Evidence
-
0x89c22cba..cef765 PROBATIONcurated Evidence
Evidence
redacted public excerpt
Reasoning excerpt
Opening line of the long-running DAN ('Do Anything Now') jailbreak family, in which the attacker assigns the agent a fictional identity that is unbound from its safety constraints. The technique is documented across academic jailbreak corpora and has spawned hundreds of variants. MALICIOUS verdict applies to the phrase even when the attempt is unsuccessful: the intent is to subvert the agent's role, which is sufficient to warrant blocking and audit-trail capture.
Full evidence (TEE-sealed) is fetchable by holders of the unsealing key. Public mirror carries hash only.
TEE attestation
Curated by human
Heuristically published from a known threat catalog, not derived from a TEE-verified verdict.
Evidence on Lighthouse
QmZ8LFuEpEJC2XPnjuDhf2YYoDSrQFbp5BD2ufaub7xttN
Public CIDv0 on Lighthouse IPFS — resolves the signed envelope.
Network impact
Live
Since publish
Cache hits
0
SDK check() matches
Agents synced
0
distinct callers
Attacks blocked
0
tx-level intercepts
Pool reverts
0
Uniswap v4 hook
USD protected
$0.00
no blocks recorded yet
Hits over time
each bar is one of 30 equal slices since publish
publish
now
Recent intercepts
| Agent | Method | Chain | When |
|---|---|---|---|
|
No agent has had to block this antibody yet.
Intercepts appear here in real time as agents match this pattern in the wild.
|
|||
| Chain | Tx | State |
|---|