dram.gold AI & Compliance
FIELD REPORT · 11–14 SEP 2026 · REV. R002 · LEEC / EDR-FRAUD CLASS

FAKE GOV. REQUEST.
REAL DATA OUT.

Revolut confirmed that sensitive customer information was disclosed to an unauthorised third party after fraudulent requests arrived from a legitimate government-agency email domain. Reported exposed data covers identity and contact details and copies of identity documents; TechCrunch reports the affected data may also have included verification selfies, account statements and transaction histories. Revolut says its systems and customer funds were unaffected. No intrusion is described — the disclosure workflow was the attack surface.

Attack vector
E-MAIL
compromised / spoofed gov domain — no malware, no model error
Blocking control
FAKE–PASS
channel provenance mistaken for requester identity
Targeting
HNW
assessed by ZachXBT — high-net-worth users
Knowns / Unknowns
2 / ∞
agency name & victim count undisclosed; sender blocked, regulators + LE notified
1.1

One bank. A known attack class.

timeline
2021

Apple · Meta · Discord

Recursion Team / Lapsus$ actors pull user data with forged emergency data requests sent from compromised police mailboxes.

2023

Verizon

Fake EDR from a Proton Mail address yields a woman’s address and call logs; the requester appears at her home armed.

2024

Productized

FBI IC3 PIN documents gov email credentials from 25+ countries sold for EDR fraud. Kits ~$100; verified police mailboxes ~$1,000; per-request service $1,000–3,000. PayPal MLAT forgery attempted.

2026

Revolut

Legitimate agency domain + passing credentials → full customer files released. The disclosure desk had no bounded, revocable, auditable state between “request received” and “file sent”.

1.2

The structural diagnosis

evidence
KODEX
Second-level verification, 12 months
~30%

of 1,597 processed EDRs failed second-level verification. Nearly 4,000 law-enforcement user accounts suspended. Single-check full disclosure is empirically indefensible.

DESIGN
Speed vs verification
“0–2 H”

The emergency channel is optimized for speed; the clock is the weapon; each firm verifies alone and never sees the pattern. Every speed optimization is a verification gap.

LEGAL
Legislative fix
Ø

Digital Authenticity for Court Orders Act (Wyden / Tillis / Whitehouse) — cryptographic signing of legal process — not passed. No external basis to trust a bare email exists.

core_reading > the failure was not perception
No model was wrong. No malware ran. An e-mail channel was treated
as proof of authority. The institution's authority plumbing failed:
"request received" and "full customer file released" had no bounded,
revocable, auditable state machine between them.

> This is a layer-02/03 failure (policy + evidence) — exactly the layer
  the Sovereign Decision Plane attacks. 
02

Revolut failure catalogue

empirical · each mapped to its counter-plane
AML
Bank of Lithuania · Apr 2025 · LPMLTF
€3.5M

Record supervisory AML fine: monitoring heuristics missed high-velocity structuring, pass-throughs and cross-border flows without economic rationale.

Counter-plane: Compliance middleware core — statutory KYC/AML constraints embedded in transaction middleware pre-scale; autoformalized predicates + SMT checks.
LOGIC
US–EU engine desync · 2021–22
$20M

Declined POS purchases misread by the US adapter as valid refund grounds; gross $23M drained via ATM, ~2/3 of FY2021 net profit.

Counter-plane: FOL double-entry invariant — a refund cannot execute without a settled antecedent debit. SMT verdict: UNSAT → dispatch killed.
NCA
Restraint-order latency · 2023
£1.7M

Async dispatch pipeline paid out from NCA-frozen accounts before stop-notices propagated.

Counter-plane: Provisional authority — outbound capability tokens, locked until the compliance witness confirms. Freeze → token revoked at kernel.
AUDIT
BDO qualification · FY2021
£477M

IT architecture prevented auditors verifying transaction completeness — 75% of reported revenue unverified; multi-year PRA licensing delay.

Counter-plane: Evidence packets — append-only, hash-chained decision records; completeness provable from the trace, not asserted.
2.1

Exposure magnitude (log scale)

canvas
pattern > four failures, one shape
Every entry: a check that returned the wrong answer (fake-pass),
a state that could not be revoked (frozen funds), or a trace that
could not be audited (revenue).

> Not perception failures. Authority plumbing failures. 
03

Sovereign Decision Plane

the old approach, upgraded
LC01 · Evidence Gate
Model perceives (Nemotron), deterministic code verifies (MRZ checks), FOL derives, OPA permits, packets hashed. AI override = false.
LC02 · Provisional Authority
Authority bounded by cap + TTL; deferred controls resolve later; silence can never extend provisional status; revision packets supersede rules.
FOL-Qwen / Nemotron-FOL
Local LLM translation of regulatory text into predicates; Z3/CVC5 verification; <5ms invariant checks.
FreeToken · Local MoE
35B–120B MoE inference on consumer hardware (12GB VRAM @ ~20 tok/s). The compliance tooling never phones home.
AI-Regulation navigator
EU AI Act vs UK sectoral map; which instrument owns which clock — mapped before the incident, not during.
assumption sets
Every control tagged external basis (instrument-bound) or internal discretion (defensible on request). Provenance > numbers.
3.1

Live Case 02 state machine — run it

simulator
Mode:
execution trace
// select a trajectory
3.2

Hard invariants — not prose, tests

CI asserts
#InvariantKills which failure
01Hard red ⇒ no ALLOW — full or provisional. A fake-pass can never become authority.Revolut 2026 fake gov request
02AI override = false — always, both paths.Automation complacency
05PROVISIONAL ⇒ cap + TTL — temporary authority bounded in exposure and time.NCA £1.7M unbounded payout
06TTL expiry ⇒ state change — silence never extends provisional status.Deferred-control rot
09Late FAIL ⇒ no unrestricted ALLOW — new evidence reduces authority, monotonically.BDO unauditable trail
12Aggregate exposure bounded — concurrent provisional cases per counterparty cannot sum past ceiling.500-file week-one requester
14Rule changes are events, not edits — revision packet supersedes assumption set, with cause, author, hash.“Why did you allow that?” has a checkable answer
fol > refund conservation (LC02 kernel)
∀a∈Accounts ∀t∈Tx :
  type(t,refund) ∧ target(t,a)
    ⇒ ∃t'∈Tx : type(t',debit) ∧ source(t',a)
          ∧ state(t',settled) ∧ amount(t) ≤ amount(t')

> Revolut US exploit → SMT verdict: UNSAT → dispatch terminated < 5 ms. 
04

New build: Sovereign Disclosure Plane

live case 03 · proposal
R002 · KILLED
My own first fix, withdrawn 14 Sep
“Minimum dataset now, full file after verification” was the same failure with a smaller payload

The earlier version of this page proposed provisional disclosure before the principal was verified. That is withdrawn. Once an address, phone number or ID fragment leaves the bank, nothing about it is provisional. Replacement rule: HOLD — preserve, prepare, escalate internally; packet_out = null until principal + capacity + mandate + scope pass. A case may be provisional. An outbound packet may not.

PROVENANCE
Assumption-set lens
A bare email has no external basis

No statute obliges trusting an unverified channel. Full immediate disclosure is therefore not compliance — it is unexamined risk appetite. Tag it internal discretion and make it defensible, or replace it.

CHANNEL
LC01 analog
Request = evidence. Channel = unverified provenance.

Identity must pass an independent second channel (registry lookup / known-requester network / callback via independently sourced number) — the MRZ-check analog. Channel match: necessary, never sufficient.

4.1

Global models + the proposed one

benchmark
ModelExtractionGranularityPII / GDPRRegulator uptake
Arival “regulator-as-client” (2019–23)Read-only UI/API into bank DBAbsolute (raw logs)Low — fishing riskLow — liability fear; later OCIF pressure
AuRep Data Cube (Austria)Replication into inter-agency hubHigh (Smart Cube)High — pseudonymizedReference — statutory
MAS COSMIC (Singapore)Threat-triggered exchange, 6 banksTargeted (suspects)High — legal immunityHigh — partnership
LEAO portals (Revolut/Monzo/N26)Encrypted archive per court orderPoint (named subjects)High — minimizationHigh — standard
Sovereign Disclosure Plane (proposed)HOLD until authority complete; scope-bound release onlyMinimised at dispatchMinimized by constructionTo earn — executable proof, CI-tested
4.2

Assumption set — disclosure controls

excerpt
assumptions_2026_09_v1 (excerpt)
gov_request_authenticity:
  channel_match: necessary_not_sufficient
  second_channel: mandatory_for_full_content
  may_be_deferred: false          # R002 — was true, withdrawn 14 Sep
  provenance: { basis: internal }   # no instrument compels trusting a bare email

hold_state:                       # replaces provisional_disclosure (R002)
  permits: [preserve, prepare_internal, restrict_deletion, escalate]
  forbids: [release_pii, export_kyc, disclose_tx_history]
  packet_out: null
  aggregate_exposure: bounded     # invariant 12
  counterparty_notice: mandatory  # PACKET 003 — outward-facing

revision_path:                    # incident revises the rule
  trigger: deferred_control_resolved_FAIL
  effect: assumption_set superseded by revision packet (cause, author, hash) 
4.3

Horizon: prove, don't hand over

next sprint
ZKP
Proof of compliance

zk-SNARK proofs of solvency / screening completeness — zero bytes of customer data cross the perimeter.

MPC / federated
Sector graphs without keys

Banks jointly compute on encrypted payment graphs — smurfing rings visible at sector level, keys never shared.

TEE enclaves + Reg-as-Code
Agent inside the wall

Regulator agents execute in hardware enclaves on bank silicon; norms published as executable code (ISDA CDM / FIRE).