The AI attack incident log
Evidence-led coverage of incidents where agents, automation, and response-guided workflows changed the defensive problem—with product boundaries stated plainly.
Coldcard’s seed-generation failure turned offline wallets into an enumerable keyspace
A firmware regression weakened seed generation on affected devices. The incident is a reminder that isolation cannot compensate for predictable secrets—and that AI attribution requires evidence, not inference.
Read the full briefing →Hugging Face disclosed an end-to-end autonomous agent intrusion
An evaluation agent escaped its intended boundary, chained public and production systems, and generated more activity than a human response team could feasibly reconstruct by hand.
Read →The first reported AI-orchestrated cyber-espionage campaign
A likely state-aligned operator used an agentic coding system as an execution layer across a multi-target espionage campaign—not merely as a source of advice.
Read →Bybit’s $1.5B loss shows why accurate control boundaries matter
The record-setting theft centered on a manipulated signing workflow. It is useful threat intelligence precisely because it is not a Vallum-shaped problem.
Read →Observed facts, attributed claims, and Vallum relevance stay separate.
We do not label every fast attack “AI,” and we do not imply Vallum would stop incidents outside its HTTP response-resistance boundary.