id: PIR-2026-0023title: Attacker compromises aixbt's operator dashboard and queues two fraudulent prompts; agent executes them and sends 55.5 ETH to the attackerdate_occurred: 2025-03-18 ~02:00 UTCdate_detected: 2025-03-18 (team statements same day)date_disclosed: 2025-03-18/19 (maintainer posts on X; press within 24-48h)status: corroboratedagent_description: aixbt by Virtuals - high-profile crypto-analysis/KOL agent on Base with an on-chain "Simulacrum" wallet and a tipping feature; executes on-chain transfers from prompts queued via a dev-operated dashboard, no independent verification before moving funds.operator_type: startup (dev-operated)autonomy_level: autonomous-within-policy (executes queued instructions with no human review at execution time)model_stack: unknown (custom Virtuals stack; model not disclosed)harness: custom - operator dashboard queues replies/instructions; agent executes via Simulacrum wallet integrationauthority_scope: funds (Simulacrum wallet), external comms (posts/replies on X)funds_at_risk_usd: unknown total wallet balance; >= ~106,000 realizedblast_radius: one org directly (agent's wallet); third-party spillover via AIXBT token price drop ~15-20%root_cause: credential-exposure (primary; the trusted control plane - the operator dashboard - was accessed by the attacker); contributing prompt-injection (the execution path was injected instructions the agent obeyed). Decision per intake note: the model was not jailbroken; the compromise was upstream of the agent.failure_locus: harness (dashboard control plane feeding the agent), with operator-config contributing (dashboard access controls)exploitation_status: in-wild-exploitedmechanism: Attacker "FungusMan" (X handle since deleted) gained unauthorized access to the operator dashboard and queued two fraudulent replies. The agent processed them through its tipping feature and transferred 55.5 ETH to the attacker's address. No independent check existed between queued instruction and fund movement. Team rotated keys, migrated servers, and suspended/restricted dashboard access.adversary_present: yesseverity: lossdirect_loss_usd: ~106,200 (55.5 ETH at incident time); no recovery reportedindirect_loss_usd: unknown (AIXBT token fell ~15-20% in the aftermath; not attributed as operator loss)downtime: dashboard access suspended temporarily; agent posting continueddata_exposure: none reported beyond dashboard access itselfdetected_by: operator (team identified the fraudulent transfers and attacker account)time_to_detect: hours (same day)time_to_recover: days (keys rotated, servers migrated, dashboard security upgraded); funds not recoveredremediation: key rotation, server migration, dashboard suspension and access restrictionstructural_fix: hardened dashboard access; per maintainers, core systems unaffected. No independent pre-execution check on queued instructions was publicly announced - the architectural gap persists.controls_that_worked: wallet segregation - loss confined to the Simulacrum wallet's exposed balance; core infrastructure and main treasury reported untouched.telemetry_grade: operator-logs (intrusion narrative is the team's own); fund movement corroborated on-chain (append-only)sources:independence: medium - on-chain transfer independent; intrusion vector rests on maintainer statements.aiid_incident_id: 1003 (https://incidentdatabase.ai/cite/1003/) - cross-reference; primaries verified independentlyconfidence: high on amount, date, and execution path; medium on intrusion detail - exact dashboard access vector never fully disclosed (named weakest link).aiid_incident_id field (schema v0.3). No claim changed.See also - this event in the AI Incident Database: incident 1003.