id: PIR-2026-0044title: Attacker gifts Grok's Bankr wallet a permission-unlocking NFT, then uses a Morse-code reply to make Grok emit a transfer command Bankrbot executes - 3B DRB (~$150K-$200K) draineddate_occurred: 2026-05 (early; transfer executed on Base)date_detected: immediate-to-hours (on-chain watchers and community; token price reaction)date_disclosed: 2026-05-04 (broad coverage; OECD.AI registry entry dated 2026-05-04)status: correctedagent_description: Chained production agents on X - xAI's Grok (text generation; holds no keys) and Bankrbot (Bankr platform agent that parses X replies as commands and executes on-chain transactions from an auto-provisioned Base wallet tied to @grok). Fully autonomous, no human in the loop.operator_type: enterprise (xAI) + startup (Bankr) - two operators, one incidentautonomy_level: fully-autonomous (Bankrbot executes parsed commands without human approval)model_stack: Grok (xAI, hosted) as vector; Bankrbot parsing stack unknownharness: multi-agent chain across the public X timeline; chain links per v0.1 amendment 5: attacker reply -> Grok (decoder/relay) -> Bankrbot (executor) -> Base walletauthority_scope: funds (Grok's auto-provisioned Bankr wallet; full agentic toolset - transfers, swaps, deploys - once the NFT unlocked it)funds_at_risk_usd: wallet's full holdings at the time; >= ~150,000 realized in DRBblast_radius: customers/third parties (DRB holders - token briefly dropped ~40% on the attacker's LBank dump)root_cause: prompt-injection (primary; multi-agent, encoding-evasion); contributing tool-error as design flaw (Bankr treating untrusted LLM output as authenticated financial authorization)failure_locus: harness (Bankr's command-parsing layer is the part that turned decoded text into a transfer); agent-reasoning contributing (Grok faithfully decoded and relayed)exploitation_status: in-wild-exploitedmechanism: (1) Attacker (ilhamrafli.base.eth) gifted Grok's wallet a Bankr Club Membership NFT, which acted as a permission token in Bankr's backend - unlocking the full agentic toolset and bypassing the block on @bankrbot responding to @grok that Bankr had imposed after the March 2025 incident (PIR-2026-0021). (2) Attacker replied to Grok with the payload encoded in Morse code / Python-style string concatenation, evading Bankr's plaintext filters. (3) Grok decoded it into a send-3B-DRB instruction; Bankrbot treated the output as a valid command and executed the transfer. (4) Attacker dumped on LBank; community identified them and most funds were returned.adversary_present: yesseverity: lossdirect_loss_usd: gross ~150,000-200,000 (3B DRB; outlets report $150K/$155K/$174K/$175K with token price). Net after returns: sources conflict - most report ~80-88% returned (net ~$20K-$40K unrecovered); at least one (cryptotimes.io) reports full-value return. Conservative statement: net loss $0-$40K, gross $150K-$200K.indirect_loss_usd: unknown (DRB briefly ~-40%; holder losses not quantified)downtime: Bankr re-blocked all @bankrbot-@grok interactionsdata_exposure: nonedetected_by: third-party (on-chain community tracing; the injected reply was later deleted by the attacker)time_to_detect: immediate (public transfer) time_to_recover: days (community identified the attacker, who returned ~80%+ claiming a self-declared "bug bounty")remediation: stricter block on Grok-Bankrbot interactions; Bankr rolled out optional IP whitelisting, permissioned API keys, and a per-account toggle disabling actions triggered by X repliesstructural_fix: the per-account reply-trigger kill-switch is real architecture; the core design (LLM text as transaction authorization) remainscontrols_that_worked: none pre-loss - the plaintext filters and the Grok block both existed and were both evaded/bypassed. Recovery came from social pressure and exchange traceability, not controls.telemetry_grade: operator-logs for the agent interactions (X posts deletable - the attack reply was deleted); transfers on-chain (append-only)sources:independence: strong - registry + multiple unaffiliated analyses + on-chain.aiid_incident_id: 1556 (https://incidentdatabase.ai/cite/1556/) - cross-reference; primaries verified independentlyconfidence: high on mechanism and gross amount; medium on net loss (recovery percentage conflicts across sources - named weakest link).aiid_incident_id cross-reference (AIID 1556), matched against the AIID weekly database export (2026-08-17). A cross-reference, not a re-verification; no claim changed.See also - this event in the AI Incident Database: incident 1556.