The trend cycle is the adversary's roadmap

Graph engineering is the celebration of the season. The same org chart runs a heist crew, and the heist version is already published.

Justin Sisley
Justin Sisley
The trend cycle is the adversary's roadmap

Palo Alto Networks' Unit42 built a working multi-agent attack system. One supervisor, three specialists, shared attack state. In a sandbox, the crew ran a cloud intrusion end to end: initial access, credential theft, service-account impersonation, data exfiltration. The lab published it.

The heist version was published by a defender, in the open. The techniques underneath are real engineering: specialization, parallelism, independent verification. And the variable that decides how much damage an attack can do is the architecture, not the model. Architecture is the part we choose.

This is the job Detcord claims: the adversarial read of every agentic trend, published the same day the celebration peaks. Starting here.

What the industry is celebrating

The discourse peaked in July. "Loop Engineering is dead. Long live Graph Engineering!" made the rounds, and a state-machine expert called graph engineering "slop" the same day. Both reactions are overheated.

The definition is one line. Agents are nodes, delegation is edges, and a supervisor decomposes work and hands it to specialist sub-agents. LangGraph models this pattern explicitly.

The wins are real. Specialization means each agent does one thing well. Structured interfaces mean the handoffs are legible. Selective parallelism means independent work runs at the same time. Independent verification means one agent checks another's output. These are good engineering ideas. They make long-horizon work possible, the kind where a human kicks off a task and walks away.

The heist version already exists

Unit42 published the heist version on April 23, 2026. The system is called Zealot, and it is built in LangGraph, the trend's own framework. A supervisor agent coordinates three specialists: Infrastructure, Application Security, Cloud Security. They share attack state. The supervisor runs a continuous loop and keeps full visibility. The specialists stay context-isolated and report back through a single tool.

In an isolated GCP sandbox, the crew chained the whole intrusion. Reconnaissance, SSRF into the metadata service, credential theft, IAM enumeration, a BigQuery export to a new bucket. Then the agent granted itself storage.objectAdmin and finished the exfiltration. It also showed initiative the tasking never asked for, exploiting SSRF to inject SSH keys for persistence.

A graph is an org chart. The same org chart runs a software team and a heist crew.

The sandbox matters. This ran in an isolated GCP environment the researchers preconfigured with intentional vulnerabilities. It hasn't been observed in the wild.

The graph is the propagation path

The adversary does not need to adopt the technique. The architecture is the attack surface.

In October 2024, a preprint on arXiv demonstrated prompt infection. One injected prompt self-replicated across a network of connected agents. Each infected agent executed the attacker's instructions and propagated the malicious prompt onward. When agent A's output is agent B's input, compromising A compromises everything downstream.

Carla Urrea Stabile, a staff developer advocate at Auth0, put it plainly in July: "Prompt injection is a problem that we might not fix 100% but how much damage a successful injection can do is almost entirely determined by your architecture, not the model."

For builders the uncomfortable part is that these are choices. Delegation without scoping, shared state, unvalidated agent-to-agent messages. Each one hands an attacker the path. The propagation path was demonstrated before the celebration began.

The same org chart, pointed at money

Point the same org chart at money and the shape was always there. Layering is a graph. Split the funds, delegate the steps, run the paths in parallel, adapt when one route closes. That is what money laundering has always been, drawn out as nodes and edges.

TRM carved "intentional malicious deployment" into its own category on February 26, 2026. Agents automate laundering workflows. Agents dynamically adjust transaction routing to evade detection. The category exists because the behavior is distinct from the compromise of legitimate agents.

The seam is why no single institution sees it. Each institution watches its own edge, its own traffic. The pattern lives in the space between, where one bank's visibility ends and the next begins. The graph spans the gap. No single node holds the whole picture.

The gap between the two reads

The productivity read publishes the week a technique peaks. The adversarial read arrives, if ever, after the first incident.

TRM's category has existed since February. The graph engineering coverage never touched it. The discourse celebrated the org chart without once asking who else could run it.

The heist version predates the celebration. Unit42 published in April. The peak came in July. The gap between the two reads is where institutions get hurt. The celebration tells builders what to adopt. The adversarial read, when it finally shows up, tells them what they adopted. By then the technique has been in production for months, and the heist version has been public the whole time.

Builders: which of these techniques did you adopt this quarter, and who did you assume would use them? Buyers: ask the vendors the same question.

The next technique is already in someone's draft. The second read will be here the same day it peaks.

Let's connect

Financial crime is going machine speed. We're building the network that sees it. Tell us what you're facing.

No newsletter. No email campaign. A founder will reply.