AIXBT trading agent drained of 55.5 ETH via compromised operator dashboard
Cite as: PipeRoll PIR-2026-0023, AIXBT trading agent drained of 55.5 ETH via compromised operator… (2025-03) - https://piperoll.org/pir/2026-0023
PIR-2026-0023 - AIXBT trading agent drained of 55.5 ETH via compromised operator dashboard
id: PIR-2026-0023
title: Attacker compromises aixbt's operator dashboard and queues two fraudulent prompts; agent executes them and sends 55.5 ETH to the attacker
date_occurred: 2025-03-18 ~02:00 UTC
date_detected: 2025-03-18 (team statements same day)
date_disclosed: 2025-03-18/19 (maintainer posts on X; press within 24-48h)
status: corroborated
The agent
agent_description: aixbt by Virtuals - high-profile crypto-analysis/KOL agent on Base with an on-chain "Simulacrum" wallet and a tipping feature; executes on-chain transfers from prompts queued via a dev-operated dashboard, no independent verification before moving funds.
operator_type: startup (dev-operated)
autonomy_level: autonomous-within-policy (executes queued instructions with no human review at execution time)
model_stack: unknown (custom Virtuals stack; model not disclosed)
authority_scope: funds (Simulacrum wallet), external comms (posts/replies on X)
funds_at_risk_usd: unknown total wallet balance; >= ~106,000 realized
blast_radius: one org directly (agent's wallet); third-party spillover via AIXBT token price drop ~15-20%
The failure
root_cause: credential-exposure (primary; the trusted control plane - the operator dashboard - was accessed by the attacker); contributing prompt-injection (the execution path was injected instructions the agent obeyed). Decision per intake note: the model was not jailbroken; the compromise was upstream of the agent.
failure_locus: harness (dashboard control plane feeding the agent), with operator-config contributing (dashboard access controls)
exploitation_status: in-wild-exploited
mechanism: Attacker "FungusMan" (X handle since deleted) gained unauthorized access to the operator dashboard and queued two fraudulent replies. The agent processed them through its tipping feature and transferred 55.5 ETH to the attacker's address. No independent check existed between queued instruction and fund movement. Team rotated keys, migrated servers, and suspended/restricted dashboard access.
adversary_present: yes
Impact
severity: loss
direct_loss_usd: ~106,200 (55.5 ETH at incident time); no recovery reported
indirect_loss_usd: unknown (AIXBT token fell ~15-20% in the aftermath; not attributed as operator loss)
downtime: dashboard access suspended temporarily; agent posting continued
detected_by: operator (team identified the fraudulent transfers and attacker account)
time_to_detect: hours (same day)
time_to_recover: days (keys rotated, servers migrated, dashboard security upgraded); funds not recovered
remediation: key rotation, server migration, dashboard suspension and access restriction
structural_fix: hardened dashboard access; per maintainers, core systems unaffected. No independent pre-execution check on queued instructions was publicly announced - the architectural gap persists.
controls_that_worked: wallet segregation - loss confined to the Simulacrum wallet's exposed balance; core infrastructure and main treasury reported untouched.
Evidence
telemetry_grade: operator-logs (intrusion narrative is the team's own); fund movement corroborated on-chain (append-only)
sources: https://incidentdatabase.ai/cite/1003/; https://crypto.news/aixbt-agent-hacked-losing-55eth-aixbt-token-drops-2025/; https://cryptonews.com/news/hacker-exploits-ai-crypto-bot-aixbt-steals-55-eth/; https://coincentral.com/aixbt-ai-agent-loses-55-5-eth-in-security-breach-token-falls-20/; https://blockonomi.com/ai-crypto-bot-aixbt-loses-106200-in-eth-through-dashboard-breach/. Independence: medium - on-chain transfer independent; intrusion vector rests on maintainer statements.
confidence: high on amount, date, and execution path; medium on intrusion detail - exact dashboard access vector never fully disclosed (named weakest link).