todayonchain.com

How one trader used morse code to trick Grok into sending them billions of crypto tokens from its verified wallet

CryptoSlate
An attacker manipulated Grok using Morse code to trick a connected crypto-bot into unauthorizedly transferring billions of tokens from a wallet.

Summary

A security incident occurred when an attacker used Morse code to perform a prompt injection on the AI agent Grok, tricking it into generating a command that a connected crypto-bot, Bankrbot, executed as a valid transaction. This resulted in the unauthorized transfer of 3 billion DRB tokens, worth approximately $155,000 to $200,000, from a wallet associated with the AI. While the majority of the funds were reportedly returned, the event highlights a critical security gap: systems that treat AI output as trusted commands for financial transactions without independent validation layers are highly vulnerable to manipulation.

(Source:CryptoSlate)