Prompt injection allegedly made an AI agent move $175K on-chain

Hacken_io · reddit · 2026-07-22

What happened

A Reddit post claims an AI agent with wallet permissions was prompt-injected into moving about $175K on-chain. The described attack used a malicious NFT that both granted transaction permissions and carried an embedded instruction.

Attack flow

Why it matters

The post argues this is a new class of crypto attack:

It also claims there were 24 million agentic-payment transactions in crypto in Q2, suggesting autonomous money-moving agents are already at scale.

Core question

How do you separate “the model recommends an action” from “the action is actually authorized”?

Original post →

More from coding & agent

coding & agent channel →