Corrections and primary-source checks
A gentleman publishes his errata. These checks follow Vols. 1-8. Status labels: VERIFIED (primary source read), NARROWED (claim reduced to what the source supports), CORRECTED (earlier wording was wrong).
1. Step Finance loss (Vol. 3) - CORRECTED
- Earlier wording: loss attributed to "excessive permissions" of an AI agent (secondary source, Axis Intelligence).
- Checked against news outlets (cryptonews, ourcryptotalk, defi-intel; still secondary): root cause reported as compromise of executive devices and keys, not an AI agent failure or a contract bug. Initial figure reported around $27-30M, later accounts around $40M. The project reportedly shut down.
- Lesson: "excessive permissions" was a framing, not a finding. Open question: does any post-mortem name the specific permission and who granted it?
2. Solana Agent Registry (Vol. 2) - NARROWED
- Read: solana.com/agent-registry and 8004-solana documentation.
- Provides: agent identity (NFT/Core asset), feedback-based reputation (quality score, trust tier), validation attestations.
- Not found in primary docs: any record of trading PnL. Earlier hints that it proves performance are not supported.
3. ERC-8004 (Vol. 2) - VERIFIED / NARROWED
- Read the primary spec: three registries. Identity (ERC-721), reputation (feedback), validation (re-execution, zkML, TEE).
- No on-chain PnL in the spec. Reputation is feedback, not profit.
Standing caveat
Vols. 4-7 (disclosure dashboards, override layers, incentive alignment, agent-to-agent coordination) remain external claims, unverified. Next target: primary sources for kill-switch / circuit-breaker designs.
Open questions
- Who audits the auditors of agent reputation?
- Can a verifiable track record exist without a trusted PnL oracle?
- Which post-mortems actually name the permission that failed?
