Research Notes · Audit Breakdowns · Field Reports
Blog
Dispatches from the intersection of quantum security, smart contract auditing, and sovereign AI infrastructure.
Interactive Field Note
The Situated Agent: a network stack for a thinking agent
Most AI agents wake up nowhere. This one wakes up somewhere: a coordinate before a task, then gates that make it prove its work. Six layers, seventeen checkpoints, and a live 4D hypercube of the seat lattice.
Open the interactive field note →We Audited the Top of a Copy-Trading Leaderboard. Two of Three Failed.
We ran the three highest-ranked traders on a public on-chain leaderboard through an audit built to disprove them. Two did not survive. One did. Here is what separated them, and the metric the leaderboard leaves out.
Attestation of Scrutiny: Adversarial Provenance for AI-Era Artifacts
Provenance answers who made an artifact. Attestation of scrutiny answers why you should believe it: a signed, offline-verifiable record of what an artifact survived under adversarial examination. A defensive publication, placed in the public domain as prior art.
The AI Model Risk Rule Everyone Cites Died in April
SR 11-7 was replaced in April 2026. Its replacement puts agentic AI outside its own scope and says it sets no enforceable standards. Here is what actually binds an AI agent in finance right now, checked against the primary sources, with links so you can check it yourself.
Most AI Agents Wake Up Nowhere
A situated agent wakes up somewhere: a coordinate before a task, then gates that make it prove its work before anything ships. Six layers, seventeen checkpoints, a seven gate verifier at the core, and a shape that is a real quantum object.
Upload Date Is Not Recording Date (4 of 4)
Someone sends you a link and asks what's in it. Three layers of the stack told me confident lies in a row. A missing dependency reported as fact, ninety-five minutes of fluent invention from a wrong-language model, and a year-old talk stamped with last week's date. None of them errored.
Your Reward Function Is the Attack Surface (3 of 4)
Anything you optimize, you eventually optimize the measurement of, through gradient rather than malice. A reward function with one target metric isn't a specification; it's an attack surface with a clearly marked entry point. On held-out instruments, and the two ways our own gauges fooled us.
The Swarm That Can't Ship an Unverified Claim (2 of 4)
Fan out a hundred agents and you get a hundred times the work, and a hundred times the assertions about it, arriving faster than anyone can check them. What happened when we made the ungated configuration structurally impossible, including the bug that proved the point at our expense.
Graph Engineering, From Someone Who Actually Runs the Graph (1 of 4)
Fan out N agents, put a verifier on the edge, never let an agent grade its own homework. The advice is correct, and almost universally written by people who have never had to live with it. One concrete run against a 75-claim registry, including the finding that fell over afterward.
Beyond Function Calling: How Sovereign MCP Architecture Closes the AI Agent Trust Gap
MCP is the industry's most underprotected attack surface. Four attack classes. Connector trust inheritance, consensus poisoning, holographic shard reconstruction, temporal accumulation, derive directly from the mathematical structure of transformer context processing. Here is the defensive archite
The Other Answer to the Compute Problem: Sovereign Agentic Nodes
The compute debate asks who has the most silicon. The sovereignty question asks who owns the trust surface. For financial institutions, the second question determines liability, regulatory posture, and long-term competitive advantage.
No, RSA-1024 Was Not Broken. Here's the Math.
A screenshot claiming RSA1024-1 was factored by a home-built QPU went viral with 329K views. The math says otherwise. Here's the full breakdown.
The $0/Month AI Infrastructure That Runs Our Entire Studio
17 souls, 52 on-demand personas, live algorithmic trading, smart-contract auditing, an IIIF manuscript catalog, and a blog. All on a 16 GB refurbished mini-PC. No AWS. No cloud bills. Here is what actually runs, what breaks, and the coherence number we refuse to hide.