Particle.news

Bankr Locks Down After AI-Layer Breach Drains 14 Wallets on Base

Researchers say a prompt-injection tricked its trading bot into signing unauthorized transactions.

Overview

  • Bankr paused swaps, transfers, and token deployments while it investigates a breach that let an attacker access 14 internal wallets.
  • The team pledged full reimbursement for affected users and told customers to stop signing transactions, move funds to new wallets, and revoke risky approvals.
  • SlowMist co-founder Yu Xian said the exploit targeted the trust link between Grok and Bankrbot, causing the bot to sign transactions it should have blocked.
  • Reporting points to prompt injection with encoded commands, such as Morse code, that one model decoded and the system treated as valid instructions.
  • Estimated losses reach at least $170,000, and the case adds to a run of attacks on automation layers and bridges, including recent incidents at Verus and Echo.