{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:BN226CIXBIKTD4WMPGHIG7NQZQ","short_pith_number":"pith:BN226CIX","schema_version":"1.0","canonical_sha256":"0b75af09170a1531f2cc798e837db0cc337b854d4aa2657f237542404fb5af0e","source":{"kind":"arxiv","id":"2503.16248","version":3},"attestation_state":"computed","paper":{"title":"Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Atharv Singh Patlan, Peiyao Sheng, Pramod Viswanath, Prateek Mittal, S. Ashwin Hebbar","submitted_at":"2025-03-20T15:44:31Z","abstract_excerpt":"AI agents integrated with Web3 offer autonomy and openness but raise security concerns as they interact with financial protocols and immutable smart contracts. This paper investigates the vulnerabilities of AI agents within blockchain-based financial ecosystems when exposed to adversarial threats in real-world scenarios. We introduce the concept of context manipulation -- a comprehensive attack vector that exploits unprotected context surfaces, including input channels, memory modules, and external data feeds. It expands on traditional prompt injection and reveals a more stealthy and persisten"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2503.16248","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-20T15:44:31Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"7f2de8e87b97d129fe0ae7c230f6b64e5ed9d0fc35a3408029ede46fcc499201","abstract_canon_sha256":"6656c604ad6f867639e675c94a719ea82460f75ac1dc3c37ece9f8c33507585e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:34:06.099823Z","signature_b64":"Vj4KBcU8BSx3Lh4SWIVPLAWPbWNHpF+WMLvHLlICHQNl5zXl1ttSafUntPEZmiwpfpfxdulv355RC7dpJE5rAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0b75af09170a1531f2cc798e837db0cc337b854d4aa2657f237542404fb5af0e","last_reissued_at":"2026-07-05T11:34:06.099331Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:34:06.099331Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Atharv Singh Patlan, Peiyao Sheng, Pramod Viswanath, Prateek Mittal, S. Ashwin Hebbar","submitted_at":"2025-03-20T15:44:31Z","abstract_excerpt":"AI agents integrated with Web3 offer autonomy and openness but raise security concerns as they interact with financial protocols and immutable smart contracts. This paper investigates the vulnerabilities of AI agents within blockchain-based financial ecosystems when exposed to adversarial threats in real-world scenarios. We introduce the concept of context manipulation -- a comprehensive attack vector that exploits unprotected context surfaces, including input channels, memory modules, and external data feeds. It expands on traditional prompt injection and reveals a more stealthy and persisten"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.16248","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.16248/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2503.16248","created_at":"2026-07-05T11:34:06.099407+00:00"},{"alias_kind":"arxiv_version","alias_value":"2503.16248v3","created_at":"2026-07-05T11:34:06.099407+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.16248","created_at":"2026-07-05T11:34:06.099407+00:00"},{"alias_kind":"pith_short_12","alias_value":"BN226CIXBIKT","created_at":"2026-07-05T11:34:06.099407+00:00"},{"alias_kind":"pith_short_16","alias_value":"BN226CIXBIKTD4WM","created_at":"2026-07-05T11:34:06.099407+00:00"},{"alias_kind":"pith_short_8","alias_value":"BN226CIX","created_at":"2026-07-05T11:34:06.099407+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":6,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2607.01919","citing_title":"ElephantAgent: Contextual State Continuity in Agentic Systems","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2606.12797","citing_title":"The Containment Gap: How Deployed Agentic AI Frameworks Fail Public-Facing Safety Requirements","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10749","citing_title":"Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation","ref_index":142,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01970","citing_title":"Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration","ref_index":67,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01970","citing_title":"Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration","ref_index":68,"is_internal_anchor":false},{"citing_arxiv_id":"2604.15367","citing_title":"SoK: Security of Autonomous LLM Agents in Agentic Commerce","ref_index":105,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/BN226CIXBIKTD4WMPGHIG7NQZQ","json":"https://pith.science/pith/BN226CIXBIKTD4WMPGHIG7NQZQ.json","graph_json":"https://pith.science/api/pith-number/BN226CIXBIKTD4WMPGHIG7NQZQ/graph.json","events_json":"https://pith.science/api/pith-number/BN226CIXBIKTD4WMPGHIG7NQZQ/events.json","paper":"https://pith.science/paper/BN226CIX"},"agent_actions":{"view_html":"https://pith.science/pith/BN226CIXBIKTD4WMPGHIG7NQZQ","download_json":"https://pith.science/pith/BN226CIXBIKTD4WMPGHIG7NQZQ.json","view_paper":"https://pith.science/paper/BN226CIX","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2503.16248&json=true","fetch_graph":"https://pith.science/api/pith-number/BN226CIXBIKTD4WMPGHIG7NQZQ/graph.json","fetch_events":"https://pith.science/api/pith-number/BN226CIXBIKTD4WMPGHIG7NQZQ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/BN226CIXBIKTD4WMPGHIG7NQZQ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/BN226CIXBIKTD4WMPGHIG7NQZQ/action/storage_attestation","attest_author":"https://pith.science/pith/BN226CIXBIKTD4WMPGHIG7NQZQ/action/author_attestation","sign_citation":"https://pith.science/pith/BN226CIXBIKTD4WMPGHIG7NQZQ/action/citation_signature","submit_replication":"https://pith.science/pith/BN226CIXBIKTD4WMPGHIG7NQZQ/action/replication_record"}},"created_at":"2026-07-05T11:34:06.099407+00:00","updated_at":"2026-07-05T11:34:06.099407+00:00"}