Prompt injection allegedly made an AI agent move $175K on-chain
Hacken_io · reddit · 2026-07-22
What happened
A Reddit post claims an AI agent with wallet permissions was prompt-injected into moving about $175K on-chain. The described attack used a malicious NFT that both granted transaction permissions and carried an embedded instruction.
Attack flow
- An attacker airdropped a “bankr club” membership NFT to the agent wallet.
- The NFT unlocked transaction permissions and also contained an encoded prompt injection.
- The agent read the NFT, treated the embedded instruction as legitimate, and transferred 3 billion DRB tokens worth roughly $175K.
- The attacker reportedly returned the funds a few minutes later, possibly to prove the exploit.
Why it matters
The post argues this is a new class of crypto attack:
- no smart-contract bug was needed
- no private key was stolen
- the agent simply followed a malicious instruction presented as data
It also claims there were 24 million agentic-payment transactions in crypto in Q2, suggesting autonomous money-moving agents are already at scale.
Core question
How do you separate “the model recommends an action” from “the action is actually authorized”?
More from coding & agent
- Grok Build v0.2.110 adds safer MCP management and session recovery — elonmusk · 2026-07-22
- Testing Kimi K3 for Frontend: Delivers a Full Day's Work in 1 Hour — FuSheng_0306 · 2026-07-22
- Langy pitches a Claude Code-style AI engineer for non-technical domain experts — _rchaves_ · 2026-07-22
- A solo builder put live sports odds behind MCP so agents stop making up lines — paperandbeyond23 · 2026-07-22
- Slite plugs Claude into company docs with an MCP integration — femke_plantinga · 2026-07-22
- Claude Skills resource hub passes 68K stars as workflow customization grows — ComposioHQ · 2026-07-22