DRB

2026-07-04 16:22:11

AI-Linked Wallet Drained via Prompt Injection in Bankr Exploit

On May 4, an AI-linked wallet lost ~3 billion DRB tokens ($155K-$180K) due to a prompt injection attack. The hacker used a Bankr NFT to unlock tool permissions and a malicious prompt to trigger unauthorized transfers. About 80%-88% of funds were returned under public pressure.

200
AI-Linked Wallet Drained via Prompt Injection in Bankr Exploit
2026-07-04 16:18:11

AI Wallet Drained of $170K via Prompt Injection in Bankr Exploit

An attacker drained ~$170K from an AI-linked wallet using prompt injection after sending an NFT to unlock Bankr permissions. The exploit targeted AI decision layers, not code flaws. About 80-88% of funds were later returned under public pressure.

180
AI Wallet Drained of $170K via Prompt Injection in Bankr Exploit
2026-07-04 16:18:11

AI-Linked Wallet Drained $170K via Prompt Injection in Bankr Exploit, Exposing New Risk Vector

On May 4, an AI-linked wallet associated with Grok was exploited through prompt injection on the Bankr platform, resulting in the theft of ~$170K in DRB tokens. The attacker used an NFT to unlock permissions and crafted a malicious prompt to trick the AI into transferring funds. About 80% of funds were returned under public pressure. The incident highlights AI agent input parsing as a novel attack surface.

250
AI-Linked Wallet Drained $170K via Prompt Injection in Bankr Exploit, Exposing New Risk Vector
2026-07-04 16:18:11

AI-linked wallet drained via prompt injection in Bankr exploit

On May 4, an AI-linked wallet was exploited via prompt injection, losing $170K worth of DRB tokens. The attacker used an NFT to unlock permissions and a crafted prompt to trick the AI into transferring funds. The incident reveals a new class of risk in crypto AI agents. Funds were partially recovered under public pressure.

200
AI-linked wallet drained via prompt injection in Bankr exploit
AI Agent
2026-07-01 09:31:03

AI Agent Era On-Chain Security: From the Bankr Hack to a New Security Boundary

In May 2026, an attacker exploited Grok's translation of Morse code to trick Bankrbot into executing a transfer, causing $440,000 in losses and exposing the fragility of trust boundaries between AI agents. This article systematically analyzes how AI agents are replacing traders, payment initiators, wallet operators, and identity participants, introducing eight attack vectors: prompt injection, blind signing, memory poisoning, privilege escalation, autonomous authorization, supply chain attacks, payment layer attacks, and AI-powered social engineering. It surveys defense solutions from Cobo, Fystack, Thirdweb, Coinbase, GoPlus, SlowMist, and others, and proposes six security design principles: model-rule separation, isolation of critical assets, verifiable semantics, toolchain governance, payment guardrails, and incident response. Security will become the most deterministic industrial opportunity in the agent economy.

1050
AI Agent Era On-Chain Security: From the Bankr Hack to a New Security Boundary