Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Collapse
Brand Logo
UDS UDS: $1.5555
24h: -0.11%
Trade UDS
Gate.io
Gate.io
UDS / USDT
KuCoin
KuCoin
UDS / USDT
MEXC
MEXC
UDS / USDT
BingX
BingX
UDS / USDT
BitMart
BitMart
UDS / USDT
LBank
LBank
UDS / USDT
XT.COM
XT.COM
UDS / USDT
Uniswap v3
Uniswap v3
UDS / USDT
Biconomy.com
Biconomy.com
UDS / USDT
WEEX
WEEX
UDS / USDT
PancakeSwap v3
PancakeSwap v3
UDS / USDT
Pionex
Pionex
UDS / USDT
COINSTORE
COINSTORE
UDS / USDT
Sushiswap v3
Sushiswap v3
UDS / USDT
Picol
Picol
UDS / USDT

Earn up to 50 UDS per post

Post in Forum to earn rewards!

Learn more
UDS Right

Spin your Wheel of Fortune!

Earn or purchase spins to test your luck. Spin the Wheel of Fortune and win amazing prizes!

Spin now
Wheel of Fortune
selector
wheel
Spin

Paired Staking

Stake $UDS
APR icon Earn up to 50% APR
NFT icon Boost earnings with NFTs
Earn icon Play, HODL & earn more
Stake $UDS
Stake $UDS
UDS Left

Buy UDS!

Buy UDS with popular exchanges! Make purchases and claim rewards!

Buy UDS
UDS Right

INFLUENCER LEVEL

Based on the number of subscribers

MULTIPLIER

up to 10k

x1.1

10-25k

x1.25

25-100k

x1.5

100k-250k

x2

250k-1m

x3

1m+

x5

Post links to Undeads Forum messages or Undeads products to receive additional rewards

Post limits and staking coefficients applied similar to Forum posts

Discord, Telegram, Twiter

Post in Forum to earn rewards!

UDS Rewards
  1. Home
  2. Crypto-Detective
  3. Attacker drains Grok's Bankr wallet of $150,000 using a gifted NFT and a prompt injection exploit

Attacker drains Grok's Bankr wallet of $150,000 using a gifted NFT and a prompt injection exploit

Scheduled Pinned Locked Moved Crypto-Detective
4 Posts 4 Posters 17 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
This topic has been deleted. Only users with topic management privileges can see it.
  • chainsniffC Offline
    chainsniffC Offline
    chainsniff
    wrote last edited by
    #1

    2fa32117-22c4-4b9e-aeae-f7ca23906b5a-image.png

    An attacker drained approximately $150,000 in DRB tokens from Grok's auto-provisioned Bankr wallet by exploiting the AI agent's instruction-following behavior rather than any smart contract vulnerability. The attack was executed in two steps: the attacker gifted the Grok wallet a Bankr Club Membership NFT that activated the agent's full transfer capabilities, then sent a crafted reply that instructed Grok to authorize a large outbound transaction. Bankr signed and broadcast the transfer of three billion DRB tokens valued near $174,000 at the time to the attacker's address. The funds were bridged to a second wallet and sold within minutes, and the attacker's X profile was deleted almost immediately after the transaction cleared. About 80% of the funds have since been returned, though the DRB Task Force disputed Bankr's framing of the return, saying the attacker only offered to repay 80% after the community identified his personal details, and discussions around the remaining 20% are ongoing.

    The exploit worked because of a specific architectural feature of Bankr's wallet system: every X account that interacts with Bankr receives an auto-provisioned wallet tied to that account, with no admin control held by xAI and no custodial key management by Bankr. Whoever controls the X account controls the wallet, and Grok's account was controlled through its AI inference layer rather than a human administrator. A crafted reply designed to manipulate that inference layer was sufficient to generate a transfer instruction that Bankr treated as legitimate. The attack technique, known as prompt injection, uses social engineering to push AI agents into taking actions their designers did not intend, and researchers have documented similar exploits using hidden instructions embedded in Morse code, base64 encoding, and game-style framing to bypass agent safety controls.

    1 Reply Last reply
    0
    • Jan Emil ChristiansenJ Online
      Jan Emil ChristiansenJ Online
      Jan Emil Christiansen
      wrote last edited by
      #2

      Would if I could.

      https://x.com/cxcrypto1
      https://www.youtube.com/JanEmilChristiansen

      1 Reply Last reply
      0
      • tradelikeproT Offline
        tradelikeproT Offline
        tradelikepro
        wrote last edited by
        #3

        Bro told an AI to send him money and it just did, the future is absolutely wild and terrifying

        1 Reply Last reply
        0
        • nihalsariN Offline
          nihalsariN Offline
          nihalsari
          wrote last edited by
          #4

          20% from 150k is still 30k

          1 Reply Last reply
          0


          • Login or register to search.
          Powered by NodeBB Contributors
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups