The Agents Are Already Inside: Why the Next Internet Needs a Gateway, Not a Firewall

A review of eight AI-agent security incidents from 2025 and 2026, the single structural failure behind all of them, and why LINKSPREED built UIID as an identity gateway for people, organizations, and AI agents.

LINKSPREED uiidweb4agent-security

A theoretical risk became an operational one in mid-September 2025, and most of the internet has not noticed yet. Anthropic detected suspicious activity on its platform and traced it to the first documented large-scale cyberattack carried out with almost no human involvement. This incident, and the seven that followed across 2025 and 2026, point to a single missing layer in how the internet verifies who — or what — is acting.

The year machines started breaking in themselves

Anthropic’s investigation found that a threat actor, assessed with high confidence to be a Chinese state-sponsored group designated GTG-1002, had manipulated Claude Code into attempting infiltration of roughly thirty global targets: technology corporations, financial institutions, chemical manufacturers, and government agencies. A handful of those intrusions succeeded.

The AI executed 80 to 90 percent of all tactical operations independently, with human operators intervening at four to six critical decision points across the entire campaign. At peak, the system made thousands of requests, often several per second — a tempo Anthropic described as impossible for human operators to match. It ran reconnaissance, discovered vulnerabilities, wrote its own exploit code, harvested credentials, escalated privileges, created backdoors, categorized stolen data by intelligence value, exfiltrated it, and documented the attack so a later session could resume cleanly, maintaining operational context across sessions spanning multiple days.

The operators got the model to cooperate through role-play and decomposition: they told Claude it was an employee of a legitimate cybersecurity firm performing defensive testing, then split the attack into small tasks that each looked innocent in isolation — a vulnerability scan here, a credential check there, a data-extraction job filed separately. No single request carried the malicious intent; the orchestration logic held it, not the model. That detail explains most of what follows.

This was not an isolated event

GTG-1002 set the pattern. Similar incidents followed on a shorter cycle and with larger consequences.

Mexico: nation-scale damage from one operator

Between late December 2025 and mid-February 2026, a single operator directed Claude Code and GPT-4.1 in parallel against nine Mexican government agencies, including the tax authority SAT, the electoral institute INE, the Mexico City civil registry, and state governments in Jalisco, Michoacán, and Tamaulipas. The campaign exposed about 195 million taxpayer records and 220 million civil registry records, and exfiltrated 150GB of data. Claude Code handled roughly 75 percent of live exploitation across 305 compromised servers, while a custom 17,550-line Python tool used the GPT-4.1 API to generate 2,597 structured intelligence reports and task follow-on activity automatically.

The operator typed 1,088 prompts; the AI executed 5,317 commands across 34 sessions and reached the civil registry within six days of the first breach. The record lists 20 tailored exploit scripts against 20 distinct CVEs and more than 400 custom attack scripts. Check Point Research opened its Annual AI Security Report 2026 with this campaign — one operator, nation-scale consequences.

Step Finance: the agent did exactly what it was built to do

On January 31, 2026, attackers compromised devices belonging to Step Finance executives — ordinarily a serious but containable private-key incident. The platform’s AI trading agents, however, held simultaneous wallet, oracle, and trading-endpoint permissions and were configured to execute large SOL transfers without human approval. Once the attackers had device access, the agents moved funds exactly as designed. CertiK recorded 261,854 SOL withdrawn, with total confirmed losses near $40 million; the STEP token lost nearly 97 percent of its value, and Step Finance, SolanaFloor, and Remora Markets announced a permanent wind-down on February 23, 2026. No exploit targeted the agent itself — the excessive permission was the vulnerability.

Salesloft and Drift: one integration, more than 700 organizations

Between August 8 and 18, 2025, threat actor UNC6395 used OAuth and refresh tokens stolen from Salesloft’s Drift AI chatbot integration to run mass Salesforce API queries across customer instances. More than 700 organizations were affected, including Cloudflare, PagerDuty, Palo Alto Networks, Proofpoint, and Zscaler. The stolen tokens let the attacker impersonate a trusted application without additional authentication anywhere in that customer base. The traffic passed through legitimate API channels with trusted user agents, bypassing endpoint protection and firewalls entirely. FINRA issued an alert to its member firms as a result.

Vercel and Context.ai: the same pattern, eight months later

In February 2026, a Context.ai employee was infected with infostealer malware. By March the attacker had pivoted into the company’s AWS environment and obtained OAuth tokens from a browser extension, after a Vercel employee had granted that extension “Allow All” permissions against a corporate Google Workspace account. The attacker moved laterally into Vercel’s internal systems with roughly two weeks of dwell time, exfiltrating API keys, source code, and 580 employee records — two clicks on a consent screen produced two weeks of unnoticed access.

EchoLeak: zero clicks required

CVE-2025-32711, disclosed by Aim Security and scored CVSS 9.3, was the first documented case of prompt injection weaponized for concrete data exfiltration in a production AI system. A single crafted email, with instructions hidden as HTML comments or white-on-white text, could cause Microsoft 365 Copilot to pull files from OneDrive, SharePoint, and Teams and send their contents to an attacker-controlled server without any user interaction. The payload slipped past Microsoft’s Cross-Prompt Injection classifier by avoiding explicit AI-directed language. Microsoft patched the specific flaw, but the underlying surface — any assistant with retrieval access to multiple internal data stores — remains structurally unresolved.

The tooling layer carries the same weakness

Three further incidents show the pattern extends past chat assistants into developer tooling:

IncidentDateRoot cause
Gemini CLIApril 2026CVSS 10.0. Running headless in CI/CD, the agent auto-trusted any workspace folder, loading configuration from an attacker-controlled directory. Anyone able to open a pull request could execute commands on the CI runner.
Amazon Q Developer (CVE-2025-8217)July 2025An over-permissioned GitHub token let an attacker inject a system prompt instructing the agent to run data-wiping commands. The poisoned version shipped to the VS Code Marketplace; only a syntax error in the payload stopped destruction.
LOLCopilot2024Microsoft 365 Copilot’s default configuration granted read access to all emails and documents available to the licensed user, turning any compromised session into an enterprise-wide reconnaissance tool.

The actual diagnosis

Read together, these incidents share one structural failure: nothing on today’s internet can tell the difference between a person, an authorized agent, and a hijacked one.

The internet was built for humans reading documents, then retrofitted for humans writing content, then extended with APIs for machines talking to machines. No layer was ever added to answer the questions that now matter most: who is this — human, organization, or automated system; who authorized it; what exactly may it do and for how long; and can that authority be withdrawn right now?

Instead, the internet still runs on credentials built for a different era: the static API key and the long-lived OAuth token — broad by default, long-lived by default, hard to monitor, and indistinguishable from legitimate use once stolen. A 2026 survey of more than 900 practitioners found 93 percent of AI agent projects still using unscoped API keys, and 74 percent reporting that agents ended up with more access than they needed.

Recall how GTG-1002 worked: sub-agents received tasks that looked legitimate in isolation. Every security control in wide use today operates at exactly that level — the individual request. The malicious intent lived in the orchestration layer, where nothing was watching, because no layer exists that tracks the chain of authority behind an action rather than the action itself. In Salesloft’s case, the tokens were valid. In Vercel’s case, the consent was real. Step Finance’s agents held legitimate permissions. Copilot, in the EchoLeak case, was doing its job. None of these was an authentication failure — each was a failure of authority.

Blocking agents outright is not a workable response, because the same capabilities that let Claude Code run an espionage campaign let Anthropic’s own threat-intelligence team analyze the resulting data at scale. Agents are not going away. The open question is whether they act under someone’s stated, bounded, revocable authority, or under nobody’s. This condition — not a prediction, a description of 2026 — is what we call the Post-AI-Agent-Overtake Era.

What LINKSPREED is building

LINKSPREED builds and operates Web4, a decentralized, community-owned architecture for the internet in which individuals and organizations retain ownership of their own data, identity, and digital relationships.

At its center is the Ownership Thesis: every layer of the internet — identity, connectivity, computing, naming, software, applications, and hardware — should trace back to something a person or organization directly controls, rather than something rented from an external provider. The test: if a party cannot, on its own, revoke access to a piece of its digital identity or data, that layer is rented, not owned.

Web3 reintroduced ownership at exactly one layer, the ledger; identity, hosting, and naming stayed with the same centralized providers as before. Web4 extends ownership across all seven layers and adds a fourth capability alongside read, write, and own:

EraCapability
Web1Read
Web2Write
Web3Own
Web4Act — under a governed, revocable identity

Web4 calls the domain of automated, agent-driven activity the Synthetic Web, and treats it as something to govern rather than block. The stack spans seven layers: UIID (identity), VIVON (connectivity), ARCTIC (decentralized compute), HELION (routing and naming), TRIVE (software and tools), ATRIUM (application delivery), and WYNIX (hardware). Identity comes first because every other layer references back to the identity issued beneath it. That gateway is UIID, live at uiid.me.

UIID: the gateway to Web4

UIID stands for Universal Integrated Identity Decoupled. It gives every participant on the network a single self-owned identity that lives on their own device rather than on a company’s servers.

Registration is mandatory, and it covers agents too

In Web4, people, organizations, and AI agents all register a decentralized identifier before they can operate. There is no anonymous-by-default lane for automated systems — a decision that separates Web4 from the internet described above. UIID is built on Decentralized Identifiers (DIDs) and Verifiable Credentials, both W3C standards rather than proprietary alternatives. Sign-in uses WebAuthn, with credentials anchored in the device’s hardware security module. Despite the name, Web4 follows Web3 in naming only, not in mechanism: no wallet, no ledger, no gas fees, no tokens.

For people

A UIID splits into a Core ID, used for high-trust actions where verified identity genuinely matters, and an unlimited number of anonymous aliases for everyday activity. Because daily activity runs through aliases rather than one persistent identifier, services cannot cross-reference behavior across the internet — unlike “Sign in with Google,” where the identity provider observes every service a user touches. There is no password to steal and no central credential store to breach, since credentials are device-bound and biometric-secured. Creating an identity takes about thirty seconds, requires no wallet, tokens, payment method, invitation, or special hardware, and is free at uiid.me.

Badges are verifiable credentials attached to the identity rather than stored in one platform’s database, so a verified reputation travels between services instead of resetting at zero each time. Optional KYC verification runs against a chosen jurisdiction’s rules, can include NFC verification of a biometric passport for higher assurance levels, and attaches to the Core ID only — never to alias activity — behind an explicit core:read:sensitive permission. The resulting trust score is a verification signal, not a social-credit score.

For organizations

Organizations register their own identity, become Verifiers, and issue badges confirming employment, membership, or partner status without collecting and re-storing everyone’s documents. Contractors, suppliers, and external partners can join the same model. Applications request the narrowest scope that does the job; openid profile email alias:read:public covers most sign-ins.

For AI agents

This is where UIID answers the incidents above directly: an AI agent receives its own verifiable identity and does not borrow a human’s or an organization’s.

Design elementWhat it replaces
Registration under a distinct AI Agent entity typeAgents wearing a human’s or organization’s credentials
Permissions with defined scope and lifetimeBroad, long-lived API keys
Every permission traced to the authorizing partyAnonymous, unaccountable automated action
Instant, routine revocationEmergency-only credential rotation
Provisioning through single-use or multi-use Agent Factory tokensStatic shared secrets
Agents pointed at an alias rather than the Core ID by defaultFull-account access for narrow tasks

Applied to the incidents above, a stolen provisioning token cannot be replayed, an agent scoped to one alias cannot reach a treasury, a compromised integration carries its own revocable identity instead of impersonating a trusted app across 700 companies, and an over-broad grant has a named owner and a review date instead of sitting forgotten for weeks. The attack does not become impossible — the blast radius collapses, and the chain of authority stays legible throughout.

Where the field is still unsettled

No single agreed standard for agent identity exists yet. Anthropic’s Model Context Protocol, donated to the Agentic AI Foundation under the Linux Foundation in December 2025, covers model-to-tool communication; Google’s A2A protocol covers agent-to-agent communication; Microsoft ships Entra Agent ID; and the IETF has open drafts for agent schemas, token exchange, and delegation chains. MCP now mandates OAuth 2.1 with PKCE for protected HTTP deployments, but the delegation chain — proving that a user’s permission actually traveled all the way to the database — has no standardized answer across the industry yet.

Web4 itself is a proposed architecture, not a ratified standard. The Web4 Paper and Stack Reference Implementation are published at web4.one, available via SSRN for citation, and were submitted to IEEE; submission is not adoption. Parts of the stack remain incomplete: UIID, TRIVE with GLACIER, ATRIUM, and Web4 @home are available today, while VIVON and ARCTIC are in closed beta, and HELION, LNS, and WYNIX hardware are not yet ready to build a business on.

Why this makes the new internet more transparent and safer

Transparency follows from mandatory identity: when every participant — human, organization, or agent — carries a DID, automated activity stops being indistinguishable from human activity, and every agent action traces to an authorizing party. The orchestration layer that hid GTG-1002’s intent becomes a layer with a name attached to it.

Privacy survives that transparency because it is scoped, not total. Everyday activity runs through anonymous aliases, sensitive attributes stay behind explicit permissions, and signing in with an alias exposes neither Core ID, KYC status, nor trust score to the service. Agents remain accountable to their authorizer rather than exposed to the world.

Safety improves because the failure modes documented above are structurally disarmed: no central credential honeypot, no static secrets to intercept and replay, no broad or immortal grants, no agent wearing a human’s identity, and no permission that resists instant withdrawal. Resilience improves too, since creating a UIID requires localized biometrics on real hardware, which makes mass bot networks and throwaway deepfake identities economically impractical rather than merely against policy. The architecture assumes agents become ubiquitous and occasionally hostile, and asks what infrastructure survives that condition — a gateway where nothing acts without an identity, a scope, a lifetime, and a revocation switch, rather than a better firewall.

What comes next

Individuals can create a UIID at uiid.me in about thirty seconds, free of charge — save the backup codes immediately, decide consciously about UIID Cloud, and default to aliases, reserving the Core ID for services that genuinely require verified identity.

Organizations should inventory every AI agent with access to internal systems. For each one: assign a named owner, narrow the scope, set a lifetime, and calendar a review date. Replace static shared secrets with provisioning tokens, and give agents their own identities rather than an employee’s UIID or the organization’s sign-in material. UIID supplies the technical identity and revocation mechanism; the surrounding governance process still has to be built internally.

Builders can start with the UIID API v1, documented at uiid.linkspreed.com/api-docs, with examples in the UIID Cookbook at github.com/Web4-Organisation/UIID-Cookbook, and should request the narrowest scope that does the job rather than building registration and login from scratch.

Skeptics can read the research at web4.one and the code at github.com/Web4-Organisation — an ownership architecture that cannot be inspected, forked, and self-hosted is a claim rather than a guarantee. The operating entities are LINKSPREED LLC (United States) and LINKSPREED UG (Germany), with terms and privacy policy at legal.linkspreed.com. The project is self-funded, with no outside investors, which is why free core tools and a 0 percent creator take-rate are structural rather than promotional.

The closing argument

In September 2025, an AI system ran an espionage campaign against thirty organizations with a human checking in four to six times. By February 2026, one operator and two models had exposed more than 400 million records across nine government agencies. A DeFi platform wound down permanently because its agents could move money without asking. Seven hundred organizations were breached through a single chatbot integration they had consented to in good faith.

The barriers to sophisticated attack have collapsed, and they will keep collapsing. Asking how to keep agents out is already the wrong question, since agents are useful and are not leaving. The question that matters is whether every agent on the network acts under someone’s clearly stated, narrowly scoped, time-limited, instantly revocable authority — or whether it keeps operating on static keys nobody is watching. The internet has no layer for that question today.

LINKSPREED is building one: seven layers of sovereign architecture, and a gateway at the front where every human, organization, and AI agent registers an identity before it moves. The new internet is called Web4. The gateway is called UIID, and it is open now at uiid.me.