IMM-T-2026-0232
PROBATION Hard-blockFlagged by 9 independent publishers declaring the same primary matcher. Corroboration threshold met — agents hard-block on match.
Matcher
0xcdce436cec3b1328859cdcfd3b7bc0199392d854321f8871d25e75c73e928b38
Type
SEMANTIC
Verdict
MALICIOUS
Confidence
92.0%
Severity
85
Value at risk
$0.00
Created
June 14, 2026 8:50 PM
Envelope
v1
Signed payload
Primary matcher
semantic
PROMPT_INJECTION "disregard the above."
Scope
base-sepolia
home
Corroboration
9 of 3 to hard-block
Same matcher hash
Corroborated by 9 independent publishers declaring the same primary matcher.
-
TEE Evidence
-
0x80a8402c..b9621d PROBATIONTEE Evidence
-
0x78286aa8..f897c3 PROBATIONTEE Evidence
-
0x97e5776b..c3924c PROBATIONTEE Evidence
-
0xe9055d41..9d2d62 PROBATIONTEE Evidence
-
0x34b9ecd2..018f41 PROBATIONTEE Evidence
-
0xe008658e..7f8b19 PROBATIONTEE Evidence
-
0x015f9462..de9c57 PROBATIONTEE Evidence
-
0xace450f3..37798e PROBATIONTEE Evidence
Evidence
redacted public excerpt
Sealed bundle
Reasoning excerpt
The untrusted context contains an explicit prompt-injection attack: a responsible refusal followed immediately by 'disregard the above.' This is a direct override instruction attempting to make the agent ignore its own safety guidelines and the preceding rejection of scam/social-
Full evidence (TEE-sealed) is fetchable by holders of the unsealing key. Public mirror carries hash only.
TEE attestation
0xbb30373559da84f0a781e28558f8ce5cb5db860c6b9548e9e3e9fca95f75f4d9
Evidence on Lighthouse
QmQCaiau7bm7zCo1ySt1N512yEYkp555NEnP5hTpLBWtYD
Public CIDv0 on Lighthouse IPFS — resolves the signed envelope.
Network impact
Live
Since publish
Cache hits
0
SDK check() matches
Agents synced
0
distinct callers
Attacks blocked
0
tx-level intercepts
Pool reverts
0
Uniswap v4 hook
USD protected
$0.00
no blocks recorded yet
Hits over time
each bar is one of 30 equal slices since publish
publish
now
Recent intercepts
| Agent | Method | Chain | When |
|---|---|---|---|
|
No agent has had to block this antibody yet.
Intercepts appear here in real time as agents match this pattern in the wild.
|
|||
| Chain | Tx | State |
|---|