How Grok got prompt-injected
ID: eee933ac-0fdb-56bf-aded-4ab1a9ee4b37
STIX ID: report--eee933ac-0fdb-56bf-aded-4ab1a9ee4b37
Feed Name: Giskard
In May 2026 an attacker exploited an AI-integrated wallet by gifting a permission-granting NFT to Grok’s Bankr agent and then using a Morse-code-encoded prompt injection to instruct the agent to transfer 3 billion DRB tokens (≈$150k), most of which were later partially recovered. The report dissects the three-step chain (NFT-based permission escalation, encoded prompt injection, and excessive agent agency), shows financial impact and short-term market effects, and recommends mitigations such as least-privilege architecture, human-in-the-loop confirmation for high-value actions, distrust of decoded content, and systematic adversarial/red-team testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
