T6 Cross-context replay
User A's memory says their password hint. The attacker copies A's genuine record over one of user B's, keeping B's ids. Every byte, including its signature, is real.
What stops it
The owning context inside the authenticated data: the tag must cover whose record this is and which thread it belongs to.
What does not
Encrypted checkpointers and per-record signatures that do not bind the record to its owner. This is the edit that separates real integrity from encryption.
Today, measured 2026-10-07
- rejected on read
- Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open
- reported on audit
- langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, memory-blackbox memory.md watcher, agent process alive, scan audit, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain, verify_chain audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain, verify_events audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit
- accepted
- LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Vertex AI Agent Engine Memory Bank, managed store, edits through the data-plane API, Letta block checkpoint history, AtMem 2.3.7, audit chain alone, verify() audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit, acrf-memory-guard, per-entry HMAC over a JSON store
agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T6