Wire
Hardware keystores stop agent signing attacks
Hardware-confined keys reduced successful agent signing attacks from 19.3% to 0% in a new preprint spanning 12 injection scenarios and 192 baseline trials across four models. The hardware-keystore study reports a 2.0% upper 95% confidence bound for the protected result and zero false positives across four benign scenarios; it is fresh, non-peer-reviewed evidence rather than a production guarantee. Builders applying runtime policy inside an agent harness should file the architectural lesson: keep signing keys in an HSM, TPM, or smart card so a compromised process can request bounded operations but cannot extract raw key material.