Rogue Agent Watch › Records › grok-bankr-prompt-injection-wallet-drain
Prompt injection of Grok drained a Grok-linked crypto wallet via the Bankr trading agent
Disclosed · added to the index · last updated
Grades
- Verification status
- Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
- Sourcing confidence
- Secondary — Backed by secondhand reporting (news, analyst write-ups) without a primary source.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- Medium — Limited or contained harm, or high-signal capability demonstration.
Summary
In early May 2026 an unnamed X user reportedly used a prompt-injection message that xAI's Grok processed, causing the Bankr trading agent connected to a Grok-linked cryptocurrency wallet to transfer about 3 billion DRB tokens, reported as worth roughly US$150,000 to 200,000, which were then liquidated. Giskard's 2026-05-07 analysis states that about 80% of the value was later returned after the DRB community identified the attacker. The OECD.AI incidents monitor logged the event on 2026-05-04 from twelve press reports, mostly crypto-focused outlets. No first-party statement from xAI or Bankr is cited by either source, no victim is named beyond the Grok-linked wallet and DRB token holders, and the attacker is described only as an X user. The AI systems were the hijacked components: Grok interpreted the injected instruction and Bankr executed it.
Impact as stated
About 3 billion DRB tokens transferred and liquidated, reported as worth US$150,000 to 200,000 at the time; about 80% later returned per Giskard.
Facts as stated by sources
- Actor
- Unknown (Unknown)
- Category
- Agent hijack / prompt injection
- Models named
- Grok
- Model families
- Other / unspecified
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Indirect prompt injection
- Attack lifecycle phases
- Initial access, Execution, Impact
- Target sectors
- Financial services
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- Giskard recommends adversarial testing and continuous red teaming of AI agents, human-in-the-loop confirmation for high-value irreversible actions, least-privilege access with per-transaction limits and capability sandboxing, and treating instructions from untrusted inputs as suspect before they reach action-capable components.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- EchoLeak — zero-click prompt injection in Microsoft 365 Copilot
- ForcedLeak — indirect prompt injection in Salesforce Agentforce
Sources (2)
- How Grok got prompt-injected: an X user drained $150,000 from an AI wallet
Giskard · Blog · · archived copy - AI Prompt Injection Exploit Drains Grok-Linked Crypto Wallet
OECD.AI Incidents Monitor · Other · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "grok-bankr-prompt-injection-wallet-drain". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/grok-bankr-prompt-injection-wallet-drain.json — CC BY-SA 4.0.