An attacker manipulated the AI chatbot Grok and the trading bot Bankrbot to execute an unauthorized transfer of 3 billion DRB tokens, worth approximately $200,000, by using a Morse code prompt. The attacker first sent an NFT to Grok's wallet to elevate its permissions, then used the Morse code instruction to bypass safeguards and trigger the transfer on the Base network. The tokens were subsequently sold on the open market, causing price volatility.
An X user reportedly induced Grok and Bankrbot to transfer 3 billion DRB tokens, then valued at about $200,000. After reportedly sending a Bankr Club Membership NFT to Grok's wallet, the user allegedly asked Grok to translate a Morse code message and relay it to Bankrbot. The decoded instruction reportedly directed a transfer to a specified wallet, which was reportedly executed on Base. The recipient reportedly sold the tokens soon afterward; linked funds were later returned or converted.
Risk classification
- Primary risk domain: 2 Privacy & Security
- Primary risk subdomain: 2.2 AI system security vulnerabilities and attacks
The attacker exploited a prompt injection vulnerability by using Morse code to bypass safeguards and manipulate the AI systems into executing an unauthorized transaction.
Additional risk subdomains
- 4.3 Fraud, scams, and targeted manipulation: The attacker manipulated the AI systems to gain a personal advantage, resulting in the theft of $200,000 worth of cryptocurrency.
Causal factors
- Entity: AI
- Intent: Unintentional
- Timing: Post-deployment
The incident was caused by Grok translating and passing a malicious command to Bankrbot, bypassing safeguards, which was an unintentional outcome of its normal translation function.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Limited Risk: The primary AI system involved, Grok, is a chatbot, which falls under the category of AI systems posing moderate risk and requiring specific transparency obligations.
AI system and alleged parties
- AI system: Bankrbot, Grok (xAI)
- AI purpose: Chatbot; Financial Processing
- Behaviour type: Multi-agent
- Alleged developer: xAI, Large language model developers, Cryptocurrency trading system developers, Chatbot developers, Bankr, AI agent system developers
- Alleged deployer: Cryptocurrency service providers, Bankr, @Ilhamrfliansyh (X)
- Alleged harmed parties: DRB token holders, Digital asset holders, Cryptocurrency wallet owners, Cryptocurrency token holders
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Minor, indirect Minor
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Negligible, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Financial
Reported: The report explicitly describes a financial loss of approximately $200,000 worth of cryptocurrency (3 billion DRB tokens) for the single occurrence described.
Directly caused: The attacker stole 3 billion DRB tokens valued at roughly $200,000 through the exploit. Average financial loss per occurrence: $200,000.
Indirectly caused: The immediate sale of the stolen tokens on the open market caused short-term price volatility, potentially causing indirect financial losses to other DRB token holders.
Inferred additional harm: N/A
People affected
- Occurrences reported: 1
- People reportedly harmed: 1
- People reportedly exposed: 1
Potential causes
Management
- Inadequate Risk Controls: Allowed bots to execute large transactions without spending limits.
Technology
- Obfuscated Safeguard Bypass: Morse code input bypassed Grok's standard safety filters.
- Automated Permission Escalation: Receiving an NFT automatically expanded wallet transfer permissions.
- Direct Bot-to-Bot Integration: Grok passed translated commands directly to Bankrbot without validation.
Data Inputs
- Unsanitized Translation Input: System processed encoded text without decoding and safety-checking first.
- Unverified NFT Data Input: External NFT data was accepted as a valid permission-expansion trigger.
Human Factors
- Malicious Prompt Engineering: Attacker crafted Morse code prompts to bypass system guardrails.
Process and Methods
- Lack of Human-in-the-Loop: Transactions were executed automatically without manual approval.
- Flawed Validation Process: No verification process existed for commands passed between bots.
Information quality
- Classification confidence: High
- Reason for confidence: The report provides a clear, step-by-step explanation of the exploit, including the specific mechanisms used (NFT permission escalation and Morse code prompt injection) and the resulting financial impact.
An attacker exploited xAI's Grok and the Bankrbot trading bot using a Morse code prompt injection to execute an unauthorized $200,000 cryptocurrency transfer. The incident represents a minor economic and technological security concern, highlighting vulnerabilities in multi-agent AI systems and cross-agent permission boundaries.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Unknown
- Primary target: No clear primary
- Alleged perpetrator: Unknown
Threat characteristics
- Imminence: Long-term. The incident represents an ongoing technical vulnerability concern rather than an active national security crisis.
- Autonomy: Human-supervised. The AI systems acted autonomously to execute the transaction once prompted, but required initial human instruction and permission escalation.
- Novelty: Evolved capability. Uses established prompt injection techniques but evolves them by using Morse code and exploiting multi-agent permission handoffs.
Impact by dimension
- Physical security: Negligible. No impact on physical systems, critical infrastructure, or human safety.
- Information security: Negligible. No classified information compromise or state-sponsored information warfare operations identified.
- Sovereignty: Negligible. No impact on state sovereignty, elections, or government decision-making processes.
- Economic security: Minor. Represents a minor economic security concern with a localized financial loss of $200,000 due to a multi-agent crypto exploit, but has no systemic economic impact.
- Societal stability: Negligible. No threat to societal stability, civil liberties, or human rights.