Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

AI-linked wallet drained via prompt injection in Bankr exploit

May 5, 2026

Drift outlines a recovery plan for users after $295 million DPRK-linked exploit

May 5, 2026

Symbiosis Integrates KyberSwap Aggregation to Revolutionize Cross-Chain Liquidity and Pricing

May 5, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»AI-linked wallet drained via prompt injection in Bankr exploit
Security

AI-linked wallet drained via prompt injection in Bankr exploit

May 5, 2026No Comments2 Mins Read

An AI-linked wallet associated with “Grok” was exploited on 4 May after an attacker used a prompt injection technique to trigger an unauthorized token transfer.

The attacker reportedly caused the wallet to send 3 billion DRB tokens, valued at roughly $155K–$180K at the time, via a command the system interpreted as legitimate.

Unlike typical exploits, the incident did not involve a smart contract vulnerability. Instead, it relied on manipulating how the AI interpreted user input.

The X account linked to the suspected attacker was later deleted, a common pattern seen in exploit cases following fund movements.

$NFT unlock enabled full wallet permissions

The attack began when the attacker sent a Bankr Club Membership $NFT to the wallet.

This $NFT reportedly unlocked advanced tool permissions within the Bankr system, enabling the AI agent to perform actions such as transfers and swaps.

Once these permissions were active, the attacker moved to the next phase — crafting a malicious prompt.

Prompt injection triggered unauthorized transfer

According to available breakdowns, the attacker used a combination of:

  • social engineering
  • obfuscated instructions [including encoded or indirect commands]

The AI interpreted the prompt as a valid instruction and generated a transfer command.

That command was then executed via Bankr’s tooling, resulting in a standard ERC-20 transaction that moved the funds to an attacker-controlled wallet.

Source: X

The tokens were subsequently transferred again and rapidly sold.

Attack relied on AI behavior, not code flaws

This incident stands out because it did not exploit a vulnerability in smart contracts or blockchain infrastructure.

Instead, it targeted:

  • intent parsing
  • tool permission systems
  • AI decision-making layers
See also  Ethereum Foundation teams up with SEAL to combat wallet drainers

The exploit demonstrates how AI agents with execution capabilities can become vulnerable when user input is not properly constrained.

Funds partially recovered after public pressure

Following the incident, reports suggest that a large portion of the funds, estimated at 80% to 88%, was returned in ETH and USDC under public pressure.

The attacker’s associated social account was later deleted.

However, details around the recovery have not been fully verified through official statements at the time of writing.


Final Summary

  • An AI-linked wallet was drained of ~$170K after a prompt injection attack tricked the system into executing a token transfer via Bankr tools.
  • The incident highlights a new class of risk in crypto, where AI agents with wallet permissions can be exploited through manipulated inputs rather than code vulnerabilities.

Source link

AIlinked Bankr drained Exploit Injection Prompt Wallet

Related Posts

Drift outlines a recovery plan for users after $295 million DPRK-linked exploit

May 5, 2026

North Korea denies TRM Labs data tying it to major crypto hacks

May 5, 2026

Crypto Detective ZachXBT Issues Serious Warning About This Altcoin! “More to Come!”

May 5, 2026

US Law Firm Launches Controversial Ethereum (ETH) Lawsuit! Here Are the Details

May 5, 2026
Top Posts

Here’s What’s in Store for Bitcoin (BTC) and the S&P 500 for Q4 2023, According to Crypto Analyst Jason Pizzino

October 3, 2023

No Real People Were Polled: AI Is Now Fabricating What “The Public Thinks”

April 8, 2026

Playnance’s G Coin surpasses 1 million holders as launch-week momentum accelerates

March 23, 2026

Type above and press Enter to search. Press Esc to cancel.