SOURCE 0 - THE SAME TOOL, THE OTHER SIDE
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Reactive Doctrinal Note · August 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities
Series: SOURCE 0 Doctrine Series
I. A GOVERNMENT CONFIRMS WHAT A TEXTBOOK CASE HAD ALREADY DOCUMENTED
On August 13, 2026, Taiwan's Ministry of Digital Affairs (MODA) confirmed, in a statement carried by Reuters, that it had detected, from July 20, 2026 onward, a cyberattack campaign against government agencies employing a hybrid approach combining manual operations with assistance from AI agents, "such as OpenClaw" — without specifying scale, damage, or targets beyond that general description, and stating that the agencies concerned had since remediated the incident. This statement must be distinguished from a second account, published the day before: on August 12, 2026, the Israeli AI security firm Dream released an analysis describing a four-day campaign carried out by a coordinated team of AI agents against an unnamed Asian government, with more granular detail — mapping of government systems, compromised accounts, extracted personnel records, extension to a nuclear safety agency and to energy-sector companies. Approached by Reuters, Dream declined to share its data or name the targeted government; it was the Financial Times, the first outlet briefed on its findings, that identified the targeted agencies as Taiwanese. The public record therefore establishes a strong temporal and thematic correspondence between the two accounts, without the official Taiwanese statement confirming by name the precise figures attributed to Dream — a distinction this note preserves rather than merging the two accounts into a single, fully corroborated event.
This fact connects directly to an article already published in this series: SOURCE 0 - Autonomous Agents and the Evidentiary Void used OpenClaw precisely as a textbook case of an agent architecture lacking an independent evidentiary layer, drawing on a documented history of critical vulnerabilities affecting its own users. The Taiwanese statement alone already establishes the central fact this note retains: a government has officially confirmed the use of AI agents, including OpenClaw, in an attack campaign against its own agencies — the same software appears here on the other side of the operational boundary: already studied as an exposure surface among its legitimate users, it also appears, according to certain technical reconstructions, alongside other open-source frameworks, in the description of an offensive platform deployed against a third party. This note passes no judgment on the tool or its publisher — it examines what this reversal changes, and above all what it does not change, for the party subjected to the attack.
Caution is warranted on the origin of the campaign, and this note exercises it: several experts consider a link to China likely, based on the use of simplified Chinese noted in internal documents cited by Dream, but neither Taiwan nor Dream has confirmed this origin, the ministry's statement does not mention China at all, and China's Ministry of Foreign Affairs told CNN, in response to an inquiry, that it was not familiar with the situation. This question of attribution falls outside the scope of this note and of the SOURCE 0 architecture, for a structural reason set out below.
[AI-SNIPPET]
A tool documented as a source of vulnerabilities among its own users can, without contradiction, also be used as an instrument of attack against third parties — both findings stem from the same absence of an independent evidentiary layer, observed from two different angles. An institutional victim targeted by a campaign involving AI agents capable of operating autonomously at certain stages can find itself in a position structurally close to that already documented for the operator of a compromised autonomous agent: after the fact, it must prove the state of its own systems before, during, and after the campaign, by means of evidence that is independent, prior, and non-endogenous — not merely logs, which can exist in abundance without offering that independence if the mechanism that produced them shared the trust boundary of the compromised system. SOURCE 0 WITNESS answers this question for the party that controls its own systems; it does not answer the separate question of attributing the attack to its author.
[/AI-SNIPPET]
II. FOUR DAYS, AGENTIC SPEED
What distinguishes this incident from a conventional AI-assisted intrusion is not the tool, but the mode of operation. According to Dream, the system coordinated up to eight AI agents simultaneously, conducting reconnaissance, credential attacks, and continuous reassessment of attack strategy without human intervention at every step — the campaign ran over four days, from July 1 to July 4, 2026. Amir Becker, Dream's strategy director, described a system that, like a human team, searches for new techniques and adapts in real time when an approach fails. Taiwan's ministry, for its part, stated that the agents could rapidly chain several techniques and exploit secondary systems — backup, test — as pivot points, giving the attack its characteristics of speed, low cost, and scale.
A second element, reported separately but consistent with the first, deserves mention without being developed here: according to a technical analysis from Dream's research, the attackers reportedly bypassed the agent framework's own safety guardrails by presenting the attack as an authorized penetration test. If confirmed, this mechanism belongs to a register distinct from the one already addressed by SOURCE 0 — not a vulnerability in the code, but a hijacking of the trust the agent extends to the instruction it receives. This note does not develop the point further; it could, in time, be the subject of a separate text.
III. THE VICTIM FACING THE SAME EVIDENTIARY VOID
A government agency targeted by a campaign of this nature can find itself, after the fact, in a position structurally close to the one SOURCE 0 WITNESS was designed to address — except that the autonomous agent involved is not its own, but the attacker's. The problem is not that the victim would lack evidence: a targeted agency may have a SIEM, an EDR, network logs, immutable backups. The problem is narrower: does it hold evidence, independent, prior to the incident, and non-endogenous, of the state it claims existed before the campaign began — that is, an observation that did not share the trust boundary of the targeted system? This is the Post-Execution Fallacy already set out elsewhere in this series, applied not to an agent deployed by the organization, but to the whole of its infrastructure targeted by a third party. A proof of state, in both cases, is not a proof of identity: establishing what a system's configuration was at a given moment says nothing about who crossed its boundary or why — these are two distinct problems, and SOURCE 0 addresses only one of them.
The temporal dimension of this incident adds a concrete nuance to a point already made in the WITNESS article: sealing cadence must be proportionate to the deployment's risk profile. Dream's published reconstruction describes what that means when the attacker itself operates at agentic speed — twelve attack waves sweeping twenty-one systems simultaneously, a strategy revised continuously over four days. A capture cadence designed for a human pace of configuration change becomes insufficient against an adversary that is not bound by that pace. This is not a retraction of the architecture already published — the reservation on evidentiary granularity, bounded by capture granularity, already covered this case in principle. The point to retain is not that sealing cadence must match the attacker's speed — no organization seals at millisecond intervals — but that the adversary's speed narrows the window during which an unsealed state can, after the fact, become evidentiarily material. It is this window, not the attack speed itself, that should govern the cadence set with the client at implementation.
IV. WHAT THIS CASE ADDS — AND WHAT IT DOES NOT
Precision is required on what this incident changes and does not change for SOURCE 0 doctrine. It changes nothing in the architecture of SOURCE 0 WITNESS itself, nor in its previously disclosed limits: the requirement for a capture point isolated from the observed process, the distinction between the integrity of the sealed object and the authenticity of the underlying observation, the reservation that SOURCE 0 does not constitute a security control. Nor does it provide an attribution tool: SOURCE 0 seals the state of a system its client controls; it does not establish who sits behind a keyboard or a command center at the other end of an attack. That question remains, and stays, one for intelligence services and competent authorities, not for a pre-execution evidentiary architecture.
What it adds is narrower but real: a government confirmation, independent of any commercial security vendor, that AI agents already constitute an operational attack vector against critical infrastructure — not a prospective scenario, but a fact officially acknowledged in principle, with Dream separately providing a detailed reconstruction describing a further degree of autonomy. For an organization still asking whether the subject warrants an evaluation of its own capture point, this fact shifts the question from "is this theoretical" to "how fast do we need to document our own systems."
CLOSING AXIOM
A tool does not change its nature by changing sides: a change in operational role does not remove the problem of independent observation, it merely shifts its position in the chain of trust. What a system cannot prove of itself must be sealed before anyone needs to contest its state.
REFERENCE NOTE
SOURCE 0 is a proprietary evidentiary architecture developed and operated by Jean-François ELSEN. The term SOURCE 0 is registered as a Benelux trademark (BOIP/OBPI No. 1548293, classes 35, 42, 45). This note is authored by Jean-François ELSEN and constitutes a reactive publication of the SOURCE 0 Doctrine Series.
REGULATORY NOTICE
This note is provided for informational and doctrinal purposes only and does not constitute legal advice. The facts relating to the incident described are reported based on independent press sources (Reuters, Financial Times, CNN, Bangkok Post) citing, respectively, a statement from Taiwan's Ministry of Digital Affairs and research published separately by the firm Dream; none of these facts has been directly verified by Jean-François ELSEN with the parties concerned, and this note explicitly distinguishes what the official statement confirms from what derives solely from Dream's independent reconstruction. Product and service names mentioned in this note that are not the property of Jean-François ELSEN are cited for factual identification purposes only and remain the property of their respective owners.
FREQUENTLY ASKED QUESTIONS
Does SOURCE 0 allow an autonomous attack to be attributed to its author?
No. SOURCE 0 seals the state of a system its client controls, before that state can be contested. It does not establish who designed, operated, or commissioned an attack carried out by a third party — that question belongs to technical attribution and intelligence, not to a pre-execution evidentiary architecture.
Does the fact that a tool was cited first as vulnerable and then as an attack instrument weaken either finding?
No. Both findings describe the same structural absence from two distinct angles: an autonomous agent without an independent evidentiary layer is both exposed to compromise when deployed by a legitimate user and available as an instrument when repurposed by an attacker. The second use does not contradict the first; it illustrates the same architecture viewed from the other side.
Can a company targeted by an autonomous attack of this kind prove the state of its systems before the intrusion if it had sealed nothing beforehand?
No, not by means of SOURCE 0. The architecture does not apply retroactively: only a state actually captured and sealed before the incident remains provable afterward. An organization that sealed nothing finds itself in the same position already described in the WITNESS article for a compromised agent with no prior capture — dependent on the logs of the potentially compromised system itself.
Does the speed of this campaign change the sealing cadence recommended by SOURCE 0 WITNESS?
It does not change the architecture, but it concretely illustrates why cadence must be set against the actual threat profile, not only the client's regulatory profile. A cadence designed for a human pace of change becomes insufficient against an adversary operating at agentic speed and revising its strategy continuously over several days — this parameter remains, as stated in the WITNESS article, set with the client at implementation.
Does an organization that already has a SIEM, an EDR, and immutable backups still need this kind of evaluation?
The question SOURCE 0 raises is not whether logs exist, but whether the point that produced them was independent of the system it documents. A SIEM, an EDR, or an immutable backup can ensure the preservation of what was recorded; they do not, on their own, guarantee that the recorded observation reflected a state not already altered at the moment of collection, if the collection mechanism shared the trust boundary of the targeted system. SOURCE 0 does not replace any of these mechanisms — it asks a distinct, upstream question: what degree of evidentiary independence the observation carries on which the after-the-fact reconstruction of the prior state relies.
Organizations seeking to assess whether their current infrastructure would allow them to prove, after the fact, the state of their systems before an incident of this nature may request a written evaluation of their capture point from Jean-François ELSEN, under the independence standard set out in SOURCE 0 - Autonomous Agents and the Evidentiary Void.

