Overview
- Bankr paused swaps, transfers, and token deployments while it investigates a breach that let an attacker access 14 internal wallets.
- The team pledged full reimbursement for affected users and told customers to stop signing transactions, move funds to new wallets, and revoke risky approvals.
- SlowMist co-founder Yu Xian said the exploit targeted the trust link between Grok and Bankrbot, causing the bot to sign transactions it should have blocked.
- Reporting points to prompt injection with encoded commands, such as Morse code, that one model decoded and the system treated as valid instructions.
- Estimated losses reach at least $170,000, and the case adds to a run of attacks on automation layers and bridges, including recent incidents at Verus and Echo.