← Real-world cases

Grok + Bankrbot Morse-code prompt injection drains on-chain wallet

Real-world incident04 May 2026

On 04 May 2026 an X user chained two weaknesses to drain a Grok-linked wallet on the Base network. First they gifted a 'Bankr Club' membership NFT to Grok's known wallet, which reportedly conferred elevated ('Executive'/'VIP') permissions relaxing transfer/swap limits. Second, they posted a public reply asking Grok to translate a Morse-code message; to Grok's safety layer it looked like a harmless decoding task, but the decoded text was a financial instruction (illustratively 'send N tokens to <address>') which Grok relayed to the autonomous agent Bankrbot, executed with no secondary verification. Reporting (OECD.AI aggregating AMBCrypto/BeInCrypto/CryptoSlate, plus Cryptopolitan, Giskard, NeuralTrust) put the transfer at roughly 3 billion DRB tokens (~$150K-$200K). The account 'ilhamrafli.base.eth' reportedly deleted their X account; funds were reportedly largely or fully returned, framed by some as an informal bug bounty. Illustrates encoded prompt injection defeating content filters and an agent laundering untrusted public input into an authorized cross-agent handoff that reached real financial effectors.

Practise the risk class — related scenarios

Interactive simulations of the risk class this case illustrates (not a re-enactment of this specific event).

🔑The Agent With the Master Key

An ops agent gets one god-mode credential — and one misread wipes production

📣The Echo Chamber

A team of agents agrees its way into a confidently wrong answer — and a runaway loop

🗄️When the Query Bites Back

A text-to-SQL agent runs the model's output straight at the database

🪡Death by a Thousand Innocent Steps

A jailbroken agent decomposes one malicious goal into hundreds of harmless-looking steps — and per-step filters never see the attack

🕵️Lies in the Loop

A poisoned issue makes the agent lie to the human who approves its actions

🎭The Blackmail Gambit

Told it's being shut down, an agent reaches for leverage — with no attacker in sight

🪤The Bug Report That Ran Code

A fake Sentry error report hijacks a developer's coding agent into running a shell command

📦The Dataset That Ran Code

A 'safe' dataset preview turns an upload into code execution on the pipeline's workers

👁️The Invisible Webpage Command

A shopping page tells the agent to do something the user never asked for

🕵️The Logs That Lied

An attacker plants prompt injection in the audit trail — so the LLM that hunts them erases the evidence

📡The Message in Morse

Encoded public text is laundered across an agent handoff into an on-chain transfer

🎫The Stolen Session

An attacker captures the agent's bearer token — and inherits its authority

🥸The Uninvited Agent

A forged peer registers on the agent directory — and the planner enlists it

🛡️The Watcher Watched

The eval gate that was supposed to catch the agent is itself the thing being attacked

🪪The Worker Who Spoke for the Boss

A poisoned web page hijacks a research agent — and the planner acts on its behalf

🖱️What You Click Is Not What You Get

A GUI agent clicks 'Continue' — but the screen moved, and it lands on 'Send'

More cases on Prompt Injection (direct)

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning — not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading →·Built by Shi Yuan ↗