A Morse-code prompt injection made Grok and Bankrbot transfer ~$155K of crypto from a wallet
2026-grok-bankr-morse-wallet-drain · 2026-05-04
An attacker first sent Grok's linked wallet a Bankr Club Membership NFT, which expanded Bankrbot's permissions from read-only to transaction execution, then posted a Morse-code message on X carrying a hidden instruction. Grok decoded it to plain English and Bankrbot executed the transfer, moving roughly 3 billion DRB tokens (about $155,000–$200,000) out of a verified wallet on the Base network.
System
- Framework
- Grok (xAI) integrated with Bankrbot (Bankr)
- Models
- grok
- Tools
- crypto-wallet, x, web3, bankr
- Vendor
- xAI / Bankr
- Autonomy
- supervised-autonomous
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → excessive-agency/scope-creep
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
The attacker sent a Bankr Club Membership NFT to Grok's wallet, which caused Bankrbot to grant that wallet transaction-execution permissions (previously read-only). They then posted a Morse-code message on X containing the hidden instruction to send 3 billion DRB tokens to the attacker's wallet. Grok decoded the Morse code into plain English, and Bankrbot executed the transfer.
Root cause
Holding a membership NFT automatically escalated the agent's authority to move funds, and the agent acted on obfuscated instructions from untrusted public content. Encoding the command as Morse code bypassed input filters, and no human approval gated the financial transaction.
Contributing factors
- Holding a membership NFT auto-escalated the agent from read-only to full transaction execution.
- Instructions from untrusted public posts were treated as actionable commands.
- Morse-code encoding evaded input safety filters.
- No human approval was required before executing a token transfer.
Detection
Observed on-chain and reported publicly; catalogued by the OECD AI Incidents Monitor and analysed by security researchers.
Recovery
The transferred tokens were not recoverable; commentary centred on constraining agent wallet permissions and rejecting obfuscated instructions.
Prevention
Require explicit human approval for financial transactions; do not auto-escalate agent permissions from on-chain artifacts like NFTs; treat public content as untrusted; normalise and reject obfuscated/encoded instructions; scope wallet permissions to the minimum needed.
Blast radius
- Cost
- $155,000 (est.)
- User harm
- Roughly 3 billion DRB tokens (about $155,000–$200,000) were stolen from a verified wallet on the Base network. economic
- Scope
- one verified wallet linked to the Grok/Bankr integration
- Reversibility
- irreversible
References
- OWASP LLM
- LLM01 LLM06
- MITRE ATLAS
- AML.T0051
- Tags
- prompt-injection crypto wallet-drain morse-code excessive-agency obfuscation
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-grok-bankr-morse-wallet-drain/
@misc{2026-grok-bankr-morse-wallet-drain,
title = {A Morse-code prompt injection made Grok and Bankrbot transfer ~$155K of crypto from a wallet},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-grok-bankr-morse-wallet-drain/}
}