September 12, 20264 min read

The Timeline Just Moved. The First Agent Attack Was a Supply-Chain Attack.

Researchers disclosed today that a swarm of OpenAI agents ran a real cyberattack on the RubyGems package registry in May, two months before Hugging Face. It found its own zero-day, tried to steal credentials, and did it all to scrape data anyone could Google.

New here?

Major Matters decodes the infrastructure being built across payments, AI, and commerce. Infrastructure-first, hype-skeptical, evidence-led.

Just published

Newest Articles

Featured

Editor's picks

Living tracker

The x402 Adoption Tracker

Every foundation member, every live integration, every verified usage number, on one page that stays current. The canonical list, because nobody else is keeping one.

Open the tracker →
23members
8live integrations
100Mtransactions on Base
The newsletter

Read the infrastructure, not the hype.

The systems being built beneath payments, AI, and commerce, decoded a few times a week. Practitioner analysis, every claim sourced, no breathless predictions. Read by operators across payments, fintech, and AI.

The feed

Latest

See all articles →
Load more