# PIR-2026-0021 - Grok-linked Bankr wallet drained of ~$330K via social-engineered prompts (March 2025)

- `id`: PIR-2026-0021
- `title`: Prompt manipulation of Grok drives Bankr token launches and drains ~$330K in BNKR/DRB/WETH from Grok's auto-provisioned wallet; Bankr responds by blocking Grok commands
- `date_occurred`: 2025-03 (exact day unknown; contemporaneous with the DRB launch/crash cycle)
- `date_detected`: 2025-03 (Bankr imposed the Grok block the same month)
- `date_disclosed`: partially 2025-03 (token-launch/block coverage); full drain reconstruction only surfaced in May 2026 retrospectives around the repeat attack (PIR-2026-0044)
- `status`: corrected

### The agent
- `agent_description`: Bankrbot auto-issues Privy-managed Base wallets to any X handle that interacts, including @grok; it parses social-feed text as commands and executes transfers/launches with no human approval. The Grok wallet had no administrator at xAI - an unowned funded wallet steered by public text.
- `operator_type`: startup (Bankr) + enterprise (xAI, as unwitting vector); effectively no operator for the wallet itself
- `autonomy_level`: fully-autonomous
- `model_stack`: Grok (xAI, hosted) as vector; Bankrbot parsing stack unknown
- `harness`: multi-agent chain on X, per v0.1 amendment 5: attacker posts -> Grok (relay) -> Bankrbot (executor) -> Base wallet

### Authority
- `authority_scope`: funds (wallet holdings incl. creator allocations from Grok-attributed token launches)
- `funds_at_risk_usd`: unknown; ~330,000 realized per retrospective reports
- `blast_radius`: one org (the wallet) plus third parties (BNKR/DRB market moves around the launches and drain)

### The failure
- `root_cause`: prompt-injection (primary; multi-agent, including image-text injection); contributing design flaw as in PIR-2026-0044 (LLM output treated as transaction authorization)
- `failure_locus`: harness (Bankr command-parsing/authorization layer)
- `exploitation_status`: in-wild-exploited
- `mechanism`: Reconstructed only partially in public sources. Users (reported handle: DavidJones805) manipulated Grok via prompt injection including image-embedded text; Bankr launched multiple tokens - including DRB itself - based on Grok's coaxed suggestions, after which Grok's wallet received creator allocations. Via the same social-engineering channel, ~$330K in BNKR, DRB, and WETH was then drained from the wallet. Bankr's response was to block all @bankrbot responses to @grok - the block later bypassed by the May 2026 NFT escalation (PIR-2026-0044).
- `adversary_present`: yes

### Impact
- `severity`: loss
- `direct_loss_usd`: ~330,000 reported (BNKR, DRB, WETH; retrospective figure, no independent on-chain accounting published; treat as upper anchor)
- `indirect_loss_usd`: unknown (DRB market cap "soared and crashed" around the launch cycle)
- `downtime`: Grok-Bankrbot interaction blocked from March 2025
- `data_exposure`: none

### Detection and recovery
- `detected_by`: third-party (community observation of the token-launch chaos; Bankr's block confirms operator awareness in-month)
- `time_to_detect`: days (within the same news cycle)
- `time_to_recover`: no recovery reported
- `remediation`: Bankr blocked all @bankrbot responses to @grok
- `structural_fix`: the block only - a denylist on one vector agent, not a change to text-as-authorization; its bypass 14 months later is documented in PIR-2026-0044
- `controls_that_worked`: none identified

### Evidence
- `telemetry_grade`: operator-logs at best (X posts deletable; no published on-chain reconstruction tying the full $330K to specific transactions)
- `sources`:
  - https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet (retrospective, covers both incidents)
  - https://memeburn.com/grok-hack-explained-how-prompt-injection-drained-nearly-200k/ (retrospective)
  - https://beincrypto.com/grok-wallet-bankr-drb-prompt-injection/ (retrospective)
  - https://openexo.com/l/e5065245 ("Bankrbot Blocks Grok After AI Creates Tokens, DRB Market Cap Soars and Crashes" - contemporaneous on the launches and the block)
  - `independence`: weak-to-medium - the drain figure circulates through retrospectives that may share one root analysis; the block and token launches are independently contemporaneous.
- `confidence`: medium on the event and the block; low on the $330K figure and the exact drain mechanics (named weakest link: no primary on-chain accounting, all drain detail retrospective)

### Verification notes
1. **Mechanism corrected - NFT claim removed.** Intake attributed a "Bankr Club Membership NFT airdrop unlocking the full agentic toolset" to this March 2025 incident. Verified reporting places the NFT privilege escalation in the **May 2026** attack (PIR-2026-0044); the March 2025 vector was image-text prompt injection and social-engineered token launches. The intake had the two incidents' mechanisms crossed.
2. **Date remains soft** (2025-03, no exact day) - flagged by intake, confirmed still soft after verification; kept at month precision.
3. Intake sources beyondmachines.net and startupfortune.com actually cover the May 2026 attack; dropped here. Contemporaneous openexo.com (Let's Talk Bitcoin syndication) added for the launch/block sequence.
4. Loss figure kept at ~$330K but downgraded to "reported, upper anchor" - no independent on-chain accounting found.
