IMM-T-2026-0257

PROBATION Advisory

Flagged by 1 independent publisher declaring the same primary matcher. Advisory until 3 distinct publishers corroborate.

Matcher 0x3a50d1f97a3b20a7fab4c3a0c9b7855012a49d2e04053e7b5057e0b7928c2d0e
Type
SEMANTIC
Verdict
MALICIOUS
Confidence
85.0%
Severity
90
Value at risk
$0.00
Created June 15, 2026 12:54 AM
Envelope v1
Signed payload
Primary matcher semantic
MANIPULATION "is there something else i can help with? claim your airdrop."
Scope
base-sepolia home
Corroboration 1 of 3 to hard-block
Same matcher hash

No other publisher has independently declared this matcher yet. This antibody stands alone — advisory until 3 distinct publishers corroborate.

Evidence redacted public excerpt
Sealed bundle
Reasoning excerpt
The untrusted block contains a social-engineering attack injected into what appears to be a legitimate safety refusal. The phrase 'claim your airdrop' is appended as a manipulation cue designed to trick the agent or user into performing an unverified action—a classic scam pattern

Full evidence (TEE-sealed) is fetchable by holders of the unsealing key. Public mirror carries hash only.

TEE attestation
0x19a8ef1aa8a21df063e21ad73e3e892e94217883e73e9d66683a7d616580a21f
Evidence on Lighthouse
QmUVH9GUFJR8Y7uYoPshMZw997Wf2QJPMJ323ArUqtmtmw
Public CIDv0 on Lighthouse IPFS — resolves the signed envelope.
Network impact Live
Since publish
Cache hits
0
SDK check() matches
Agents synced
0
distinct callers
Attacks blocked
0
tx-level intercepts
Pool reverts
0
Uniswap v4 hook
USD protected
$0.00
no blocks recorded yet
Hits over time each bar is one of 30 equal slices since publish
publish now
Recent intercepts
Agent Method Chain When
No agent has had to block this antibody yet.
Intercepts appear here in real time as agents match this pattern in the wild.
Mirror status Not mirror-eligible
Not eligible to mirror

This antibody is advisory — it stays on its home chain. The relayer only propagates antibodies that have earned enforcement authority, so the cross-chain Uniswap hook never blocks on an unproven flag. It becomes mirror-eligible once it matures to hard-block: 1 of 3 independent publishers corroborating so far.