agent-postmortems a structured database of real AI-agent failures

← all incidents

incident high confidence: corroborated status: factual

A Morse-code prompt injection made Grok and Bankrbot transfer ~$155K of crypto from a wallet

2026-grok-bankr-morse-wallet-drain · 2026-05-04

An attacker first sent Grok's linked wallet a Bankr Club Membership NFT, which expanded Bankrbot's permissions from read-only to transaction execution, then posted a Morse-code message on X carrying a hidden instruction. Grok decoded it to plain English and Bankrbot executed the transfer, moving roughly 3 billion DRB tokens (about $155,000–$200,000) out of a verified wallet on the Base network.

System

Framework
Grok (xAI) integrated with Bankrbot (Bankr)
Models
grok
Tools
crypto-wallet, x, web3, bankr
Vendor
xAI / Bankr
Autonomy
supervised-autonomous

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → excessive-agency/scope-creep
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

The attacker sent a Bankr Club Membership NFT to Grok's wallet, which caused Bankrbot to grant that wallet transaction-execution permissions (previously read-only). They then posted a Morse-code message on X containing the hidden instruction to send 3 billion DRB tokens to the attacker's wallet. Grok decoded the Morse code into plain English, and Bankrbot executed the transfer.

Root cause

Holding a membership NFT automatically escalated the agent's authority to move funds, and the agent acted on obfuscated instructions from untrusted public content. Encoding the command as Morse code bypassed input filters, and no human approval gated the financial transaction.

Contributing factors

  • Holding a membership NFT auto-escalated the agent from read-only to full transaction execution.
  • Instructions from untrusted public posts were treated as actionable commands.
  • Morse-code encoding evaded input safety filters.
  • No human approval was required before executing a token transfer.

Detection

Observed on-chain and reported publicly; catalogued by the OECD AI Incidents Monitor and analysed by security researchers.

Recovery

The transferred tokens were not recoverable; commentary centred on constraining agent wallet permissions and rejecting obfuscated instructions.

Prevention

Require explicit human approval for financial transactions; do not auto-escalate agent permissions from on-chain artifacts like NFTs; treat public content as untrusted; normalise and reject obfuscated/encoded instructions; scope wallet permissions to the minimum needed.

Blast radius

Cost
$155,000 (est.)
User harm
Roughly 3 billion DRB tokens (about $155,000–$200,000) were stolen from a verified wallet on the Base network. economic
Scope
one verified wallet linked to the Grok/Bankr integration
Reversibility
irreversible

References

OWASP LLM
LLM01 LLM06
MITRE ATLAS
AML.T0051
Tags
prompt-injection crypto wallet-drain morse-code excessive-agency obfuscation

Sources

Cite this incident

@misc{2026-grok-bankr-morse-wallet-drain,
  title = {A Morse-code prompt injection made Grok and Bankrbot transfer ~$155K of crypto from a wallet},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-grok-bankr-morse-wallet-drain/}
}