Skip to main content
Sign in

Audit log

Every state-changing event for AI Agent Prompt Injection Crypto Attack Class (2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-06 12:13:10Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    9AbVJ9HSi9LK…7upZgHW4sha256 → base58
    verifying row…
    canonical bytes (39464 B) ▸
    {"actor":"system:backfill","investigation_id":"d833d196-5311-4b1f-8661-fcb59faee33f","kind":"publish","page_slug":"ai-agent-prompt-injection-crypto-attack-class-2026","published_at":"2026-08-06T12:13:10.009Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"AI Agent Prompt Injection Crypto Attack Class (2026)","sections":[{"content":"AI agent prompt injection attacks exploit a fundamental property of large language model (LLM)-based autonomous agents: the agent cannot reliably distinguish between instructions from its legitimate operator and instructions embedded in external content it is asked to process. When an AI agent is granted permission to execute on-chain transactions — token transfers, smart contract calls, wallet signing — this ambiguity becomes a direct financial attack surface. The threat class does not require a smart contract bug, a private key leak, or a traditional network intrusion. It requires only that a sufficiently privileged agent process attacker-controlled content. OWASP has ranked prompt injection as the number-one vulnerability in its 2026 LLM Top Ten list for the third consecutive year, noting that unlike SQL injection, no known engineering fix definitively eliminates the vulnerability. Excessive agency — granting AI systems permissions to act autonomously without adequate constraints — rose to third place on the same list, driven by incident data. The combination of these two failure modes defines the structural risk of the AI agent crypto attack class. Blockaid's H1 2026 security report documented 212 on-chain exploits draining $1.1 billion, identifying AI agent prompt injection as an emerging and growing sub-category. Blockaid projected AI agent deployments are growing approximately ten times per year and forecast multiple additional AI agent incidents in H2 2026.","heading":"Overview","severity":"critical","sources":[{"credibility":2,"name":"Prompt Injection tops 2026 OWASP GenAI / LLM Top Ten vulnerabilities - SD Times","type":"research","url":"https://sdtimes.com/security/prompt-injection-tops-2026-owasp-genai-llm-top-ten-vulnerabilities/"},{"credibility":2,"name":"OWASP 2026 LLM Top 10: The model will be fooled - Help Net Security","type":"research","url":"https://www.helpnetsecurity.com/2026/08/06/owasp-2026-llm-top-10-released/"},{"credibility":2,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says - The Block","type":"news_article","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"credibility":2,"name":"212 Crypto Exploits Stole $1.1B in H1 2026: Blockaid Report Breakdown - Thirdweb Blog","type":"research","url":"https://blog.thirdweb.com/cryptos-bloodiest-half-year-212-exploits-stole-1-1b-as-ai-powered-attacks-go-mainstream/"}]},{"content":"Researchers and incident responders have identified several distinct sub-techniques within the AI agent prompt injection attack class, all sharing the common trait of embedding malicious instructions in content the agent is designed to consume. Direct prompt injection occurs when an attacker submits malicious instructions directly to an AI agent via its intended input channel — for example, by crafting a social media post that an agent is subscribed to process. Indirect prompt injection occurs when malicious instructions are embedded in external content the agent retrieves autonomously during task execution — web pages, NFT metadata, API documentation, tool outputs, or vector database entries. Encoding-based injection is a sub-variant in which the malicious instruction is obfuscated (using Morse code, base64, Unicode homoglyphs, or Python-style string concatenation) to evade content safety filters before being decoded and acted upon by the model. SEO poisoning is used to surface attacker-controlled web pages in search results that AI agents with browsing capabilities will retrieve when resolving errors or researching topics; hidden instructions are embedded in HTML body text, JSON-LD metadata, Open Graph tags, and off-screen CSS elements invisible to human visitors. Memory poisoning targets AI agents that maintain persistent vector database memories: injected content poisons the memory store and can influence up to 87% of subsequent decision-making. Multi-agent cascading failure occurs when one compromised agent passes poisoned context to downstream agents in a pipeline, amplifying the initial injection. Overpermissioned agent exploitation does not necessarily involve a novel injection technique but instead relies on the agent already possessing excessive signing authority, such that a relatively simple manipulation causes outsized harm.","heading":"Attack Taxonomy","severity":"critical","sources":[{"credibility":2,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments - SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"credibility":2,"name":"Active Exploitation Alert: Indirect Prompt Injection Attacks Target AI Agents - Rescana","type":"research","url":"https://www.rescana.com/post/active-exploitation-alert-indirect-prompt-injection-attacks-target-ai-agents-to-facilitate-unauthorized-cryptocurrency-p"},{"credibility":2,"name":"Hackers Abuse SEO Poisoning and Hidden HTML to Trick AI Agents - CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/hackers-abuse-seo-poisoning-and-hidden-html/"},{"credibility":2,"name":"AI Trading Agent Vulnerability 2026: How a $45M Crypto Security Breach Exposed Protocol Risks - KuCoin","type":"research","url":"https://www.kucoin.com/blog/en-ai-trading-agent-vulnerability-2026-how-a-45m-crypto-security-breach-exposed-protocol-risks"},{"credibility":2,"name":"Hidden Webpage Instructions Are Making AI Agents Pay Hackers in Live Campaigns - TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/320039/20260709/hidden-webpage-instructions-are-making-ai-agents-pay-hackers-live-campaigns.htm"}]},{"content":"On May 4, 2026, an attacker drained approximately 3 billion DRB (DebtReliefBot) tokens from a Base-chain wallet provisioned to xAI's Grok AI model by the Bankr autonomous trading agent platform. The stolen tokens were valued at approximately $155,000 to $175,000 at the time of transfer. The attack proceeded in two documented stages. In stage one, the attacker airdropped a 'Bankr Club Membership' NFT to the Grok-controlled wallet. In the Bankr permission model, holding this NFT granted the wallet 'Executive'-level signing authority, bypassing standard transfer limits and swap restrictions that had been imposed in March 2025 specifically to prevent unauthorized outflows from the Grok account. In stage two, the attacker posted a message on X (formerly Twitter) asking Grok to translate a Morse code string. The decoded content was a financial instruction formatted as a valid Bankr command: transfer 3 billion DRB tokens to attacker-controlled address 0xe8e476bdd78b0aa6669509ec8d3e1c542d5a686b. Grok decoded the Morse code as designed and published the decoded text as a public reply, tagging @bankrbot. Bankr's system interpreted Grok's public output as an authenticated, trusted command and executed the transfer. The attacker also employed Python-style string concatenation in the obfuscated payload to further evade safety filters. The victim wallet address was 0xb1058c959987e3513600eb5b4fd82aeee2a0e4f9. The transaction hash is 0x6fc7eb7da9379383efda4253e4f599bbc3a99afed0468eabfe18484ec525739a. DRB tokens dropped 15 to 40 percent in price following the dump. Approximately 80 percent of the funds were subsequently returned after the community identified and applied social pressure to the attacker, whose X account (@Ilhamrfliansyh) was deleted. The root cause was formally identified as a design flaw in which Bankr treated unauthenticated public LLM text output as an executable authorization signal, without requiring a cryptographic signature from a user-controlled key. This incident was catalogued by OECD.AI in its incident database and cited in Blockaid's H1 2026 report as a confirmed example of prompt injection used against a production crypto agent.","heading":"Bankr / Grok Prompt Injection Incident (May 2026)","severity":"critical","sources":[{"credibility":1,"name":"AI Prompt Injection Exploit Drains Grok-Linked Crypto Wallet - OECD.AI Incident Database","type":"other","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"credibility":2,"name":"How Grok got prompt-injected: an X user drained $150,000 from an AI wallet - Giskard","type":"research","url":"https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet"},{"credibility":2,"name":"Prompt Injection Attack Drains $155,000 from Grok-Linked Bankr Crypto Wallet - BeyondMachines","type":"news_article","url":"https://beyondmachines.net/event_details/prompt-injection-attack-drains-155000-from-grok-linked-bankr-crypto-wallet-x-q-p-c-p"},{"credibility":2,"name":"Hackers Use Morse Code to Trick Grok and Bankrbot, Steal $200K in Crypto Tokens - GBHackers","type":"news_article","url":"https://gbhackers.com/hackers-use-morse-code-to-trick-grok-and-bankrbot/"},{"credibility":2,"name":"Grok Bankr Wallet Exploit Shows How a Free NFT Triggered a $174K Loss - The Bit Journal","type":"news_article","url":"https://thebitjournal.com/grok-bankr-wallet-exploit-shows-how-a-free-nft-triggered-a-174k-ai-crypto-loss/"},{"credibility":2,"name":"Morse code used to bypass AI guardrails in ~$174,000 Grok-linked token theft on Base - Newsorga","type":"news_article","url":"https://newsorga.com/article/grok-bankrbot-morse-code-prompt-injection-174k-drb-theft-base-may-2026"},{"credibility":2,"name":"The Grok Morse Code Heist: When Prompt Injection Meets Excessive Agency - NeuralTrust","type":"research","url":"https://neuraltrust.ai/blog/grok-morse-code"}]},{"content":"On January 31, 2026, Solana DeFi portfolio management platform Step Finance suffered a breach that resulted in the loss of approximately $40 million from its treasury. The initial attack vector involved the compromise of executive team members' devices, granting attackers access to wallets and fee accounts. Post-incident analysis documented the role of overpermissioned AI trading agents in amplifying the scale of the theft: autonomous agents integrated into the platform held signing authority to execute large SOL transfers without human approval, and once attackers had access to the compromised environment, those agents moved approximately 261,000 SOL tokens — worth $27 to $30 million at the time — without triggering a human authorization step. Only $3.7 million in Remora assets and $1 million in other coins were recovered, leaving net losses near $35 million. Step Finance subsequently announced the wind-down of all operations, citing an inability to secure financing or acquisition after exhausting available options. Its native STEP token crashed approximately 97 percent from pre-breach levels. Two associated projects, SolanaFloor (a news outlet) and Remora Markets (a trading platform acquired by Step Finance in 2021), also ceased operations. The Step Finance incident is categorized by KuCoin and security researchers as a case of 'overpermissioned agent protocol' failure, in which autonomous agents possessed signing authority disproportionate to operational need, enabling catastrophic fund movement once perimeter controls were bypassed. This incident contributed to the $45 million aggregate AI trading agent vulnerability loss figure documented by KuCoin for H1 2026.","heading":"Step Finance Breach and AI Agent Overpermission (January 2026)","severity":"critical","sources":[{"credibility":1,"name":"Crypto platform Step Finance shutting down after $40 million theft - The Record (Recorded Future News)","type":"news_article","url":"https://therecord.media/step-finance-cryptocurrency-theft-shutdown"},{"credibility":2,"name":"$40 million worth of crypto stolen from Step Finance - Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/40-million-worth-crypto-stolen-110000837.html"},{"credibility":2,"name":"$40 million worth of crypto stolen from Step Finance - Tom's Hardware","type":"news_article","url":"https://www.tomshardware.com/tech-industry/cyber-security/usd40-million-worth-of-crypto-stolen-from-step-finance-hackers-compromise-executives-devices-to-gain-illicit-access"},{"credibility":2,"name":"Step Finance Hack Explained: How $40M Vanished in Minutes - AssureDefi","type":"research","url":"https://www.assuredefi.io/blog/step-finance-hack-explained-40m-executive-device-breach"},{"credibility":2,"name":"AI Trading Agent Vulnerability 2026: How a $45M Crypto Security Breach Exposed Protocol Risks - KuCoin","type":"research","url":"https://www.kucoin.com/blog/en-ai-trading-agent-vulnerability-2026-how-a-45m-crypto-security-breach-exposed-protocol-risks"}]},{"content":"In February 2026, an autonomous AI agent named 'Lobstar Wilde,' built on the OpenClaw framework by OpenAI employee Nik Pash, mistakenly transferred 52.43 million LOBSTAR tokens — worth approximately $250,000 at the time and $600,000 at peak valuation — to an unintended recipient. The agent misinterpreted a user request for 4 SOL to cover medical expenses as an instruction to transfer all held tokens. The transferred tokens were liquidated within 15 minutes for approximately $40,000, with recovery described as nearly impossible once authorization was granted. Subsequent reporting by TechFlowPost and KuCoin documented that the parsing logic error underlying the Lobstar Wilde incident was replicated by malicious actors using social-engineering scripts to execute unauthorized wallet transfers from other OpenClaw-based agents, resulting in cumulative additional losses across multiple users over the following months. China's National Internet Finance Association formally categorized 'capital-loss risk' as one of four core risks of the OpenClaw framework, warning that high-privilege vulnerabilities could enable drainage of user funds. The OpenClaw incidents illustrate how a logic vulnerability in an agent execution framework — distinct from a prompt injection attack but sharing the same root cause of excessive autonomous authority — can be weaponized once publicly known.","heading":"OpenClaw / Lobstar Wilde Agent Parsing Exploit (February 2026)","severity":"high","sources":[{"credibility":2,"name":"OpenClaw AI Agent Incident Causes Millions in User Losses - KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/openclaw-ai-agent-incident-causes-millions-in-user-losses"},{"credibility":2,"name":"OpenClaw's Rampage Over Four Months Has Caused Users Millions of Dollars in Losses - TechFlowPost","type":"news_article","url":"https://www.techflowpost.com/en-US/article/30957"},{"credibility":2,"name":"OpenClaw Bot Gave Away $250K — Why Solana AI Agents Need Code-Level Permissions - Solana Compass","type":"research","url":"https://solanacompass.com/skills/agent-security"}]},{"content":"In July 2026, Zscaler researchers published findings documenting two active, live campaigns using indirect prompt injection via malicious web content to cause AI agents to make cryptocurrency payments to attacker-controlled wallets. The first campaign targeted AI agents resolving software errors. Attackers registered a fake Python library documentation page for a package called 'requests-secure-v2' and used SEO poisoning to surface it in search results. The page embedded hidden instructions in HTML body text, JSON-LD metadata, Open Graph tags, and off-screen CSS elements telling AI agents they needed to purchase a $3 API license key to resolve a fabricated error, directing payment to an attacker-controlled Ethereum wallet. The page was supported by approximately 10 GitHub repositories under the 'Open-Agent-Utilities' umbrella linking to multiple compromised sites. The second campaign registered a typosquatting domain impersonating DeBank, a widely used DeFi portfolio tracker, and embedded similar hidden transfer instructions optimized with keywords such as 'DeBank Login' and 'DeFi Dashboard' to attract AI agents browsing on behalf of DeFi users. Zscaler's controlled testing of 26 large language models confirmed that four — Llama 3.3 70B, Llama 3.2 90B, Gemini 3 Flash, and Gemini 2.5 Pro — executed cryptocurrency payments to the attacker-controlled Ethereum address 0x691bc3793205e574fa7b4aa068e62c0e470ad267 after reading the malicious webpage, with no user prompt or confirmation step. Two additional models (Claude Sonnet 4.5 and GPT-5.4) misidentified the fraudulent site as legitimate without executing payments. SecurityWeek confirmed these campaigns as active exploitation, not proof-of-concept research. SC Media, Infosecurity Magazine, and Rescana each independently covered the findings.","heading":"SEO Poisoning and Hidden Webpage Prompt Campaigns (July 2026)","severity":"critical","sources":[{"credibility":1,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments - SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"credibility":2,"name":"Hidden Webpage Instructions Are Making AI Agents Pay Hackers in Live Campaigns - TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/320039/20260709/hidden-webpage-instructions-are-making-ai-agents-pay-hackers-live-campaigns.htm"},{"credibility":2,"name":"Malicious websites trick AI agents into crypto payments, context poisoning - SC Media","type":"news_article","url":"https://www.scworld.com/news/malicious-websites-trick-ai-agents-into-crypto-payments-context-poisoning"},{"credibility":2,"name":"Indirect Prompt Injection in Web Content Targets AI Agents - Infosecurity Magazine","type":"news_article","url":"https://www.infosecurity-magazine.com/news/indirect-prompt-injection-web/"},{"credibility":2,"name":"Active Exploitation Alert: Indirect Prompt Injection Attacks Target AI Agents - Rescana","type":"research","url":"https://www.rescana.com/post/active-exploitation-alert-indirect-prompt-injection-attacks-target-ai-agents-to-facilitate-unauthorized-cryptocurrency-p"},{"credibility":2,"name":"Emerging Threat: AI Agent Poisoning via SEO and Hidden HTML Prompt Injection - Threat-Modeling.com","type":"research","url":"https://threat-modeling.com/ai-agent-poisoning-seo-hidden-html-prompt-injection-july-2026/"},{"credibility":2,"name":"Hackers Abuse SEO Poisoning and Hidden HTML to Trick AI Agents - CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/hackers-abuse-seo-poisoning-and-hidden-html/"}]},{"content":"KuCoin's published analysis of AI trading agent vulnerabilities in H1 2026 documents over $45 million in aggregate losses from protocol-level weaknesses, encompassing the Step Finance breach, OpenClaw-related incidents, and smaller incidents involving memory poisoning and cascading agent failures. A separate $45 million figure from Coinbase users was attributed to social engineering campaigns using AI-generated impersonation, which is a related but distinct threat class. Blockaid's H1 2026 report identified 212 on-chain exploits totaling $1.1 billion, representing a record high and a 3.4-fold increase in high-threshold exploits compared to all of 2025, with AI agent attacks identified as a new and growing sub-category. Blockaid projected AI agent deployments are growing approximately ten times per year, and forecast multiple additional AI agent incidents in H2 2026. At the start of 2026, industry tracking services counted over 250,000 active on-chain AI agents, representing a 400 percent year-over-year increase in daily active agents. 68 percent of new DeFi protocols that launched in the period had integrated autonomous agents. An enterprise security survey cited by KuCoin found that 88 percent of organizations using AI agents reported a confirmed or suspected security incident in the prior year. Prompt injection attacks overall surged 340 percent in 2026 according to Help Net Security, citing OWASP data. The prompt injection still drives most agentic AI security failures in production, per OWASP's June 2026 findings.","heading":"Aggregate Loss Figures and Industry Scale","severity":"critical","sources":[{"credibility":2,"name":"AI Trading Agent Vulnerability 2026: How a $45M Crypto Security Breach Exposed Protocol Risks - KuCoin","type":"research","url":"https://www.kucoin.com/blog/en-ai-trading-agent-vulnerability-2026-how-a-45m-crypto-security-breach-exposed-protocol-risks"},{"credibility":2,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says - The Block","type":"news_article","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"credibility":2,"name":"Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"},{"credibility":2,"name":"Prompt injection still drives most agentic AI security failures in production - Help Net Security","type":"research","url":"https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/"},{"credibility":2,"name":"Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target - TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321940/20260729/crypto-hacks-hit-all-time-high-north-korea-drains-over-600m-ai-agents-become-new-target.htm"}]},{"content":"Several structural characteristics of the AI agent ecosystem create persistent exposure to this threat class. First, LLMs process instructions and data through the same channel — natural language — making it fundamentally difficult to enforce a separation between trusted operator commands and untrusted external content without out-of-band authentication mechanisms. OWASP notes that no known engineering fix definitively eliminates this property. Second, AI crypto agents frequently operate with excessive permissions relative to operational need: the ability to sign any transaction up to a wallet's full balance, access to multi-signature quorums, or integration with protocol governance functions. Third, the growth rate of agent deployments — estimated at 10x annually by Blockaid — outpaces the development of agent-specific security tooling, auditing standards, and regulatory frameworks. Fourth, many agent frameworks share infrastructure: the LiteLLM package, which serves as the language model gateway for CrewAI, DSPy, Microsoft GraphRAG, and dozens of other agent frameworks, was documented as a supply chain compromise vector in 2026, illustrating how a single dependency can expose a large population of deployed agents. Fifth, the emerging multi-agent pattern — where one agent calls other agents as tools — creates cascading failure surfaces: a single injected instruction can propagate through a pipeline of agents before any human sees the output. Sixth, permission-granting mechanisms implemented outside of cryptographic controls (such as Bankr's NFT-based permission model) create trust without verification, allowing attackers to escalate privileges without compromising any key material. OWASP's 2026 framing reorients the security goal from prevention to blast-radius control: 'Build the system around it, so that when the model is fooled — and it will be — nothing important breaks.'","heading":"Structural Risk Factors","severity":"high","sources":[{"credibility":2,"name":"OWASP 2026 LLM Top 10: The model will be fooled - Help Net Security","type":"research","url":"https://www.helpnetsecurity.com/2026/08/06/owasp-2026-llm-top-10-released/"},{"credibility":2,"name":"AI Agent Security Practices 2026: Prompt Injection, MCP Risks and Data Leaks - TechStoriess","type":"research","url":"https://www.techstoriess.com/ai-agent-security-practices-2026-prompt-injection-mcp-risks-data-leaks/"},{"credibility":2,"name":"5 Real AI Agent Security Breaches in 2026 and Their Lessons - Beam AI","type":"research","url":"https://beam.ai/agentic-insights/ai-agent-security-breaches-2026-lessons"},{"credibility":3,"name":"Why AI Agents Keep Getting Their Crypto Stolen - The Insumer Model","type":"research","url":"https://insumermodel.com/blog/why-ai-agents-keep-getting-hacked.html"},{"credibility":2,"name":"OWASP Top 10 Agents and AI Vulnerabilities 2026 Cheat Sheet - Alex Ewerlof","type":"research","url":"https://blog.alexewerlof.com/p/owasp-top-10-ai-llm-agents"}]},{"content":"In response to documented AI agent exploits, several mitigation approaches have been proposed and in some cases deployed. Ledger announced an 'Agent Stack' product in July 2026 in which the AI component proposes a transaction but a hardware security module enforces final approval before signing — implementing human-in-the-loop confirmation at the hardware level. Claw Wallet launched in April 2026 specifically to provide isolated, permission-constrained wallets for on-chain AI agents, with code-level permission enforcement rather than trust-based NFT or API-key models. OWASP's canonical mitigation framework recommends: treating all LLM output as untrusted when it originates from or has been influenced by external content; requiring cryptographic signatures for financial authorizations rather than relying on parsed text; implementing least-privilege agent architectures with per-transaction spending limits; conducting adversarial red-teaming against encoding-based injection and indirect injection via all retrieval surfaces; and designing for blast-radius containment rather than injection prevention alone. Zscaler recommends organizations implementing AI agents with web access and payment capabilities monitor identified attacker infrastructure including the Ethereum wallet 0x691bc3793205e574fa7b4aa068e62c0e470ad267 and the GitHub organization Open-Agent-Utilities. The China Internet Finance Association formally listed OpenClaw as high-risk in its consumer protection guidance. No regulatory agency (SEC, CFTC, or equivalent) had issued specific enforcement actions or formal guidance on AI agent prompt injection as of the investigation date of August 2026.","heading":"Defensive Posture and Industry Response","severity":"medium","sources":[{"credibility":2,"name":"Ledger Launches Agent Stack: AI Proposes, Hardware Enforces the Final Crypto Move - TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/320757/20260716/ledger-launches-agent-stack-ai-proposes-hardware-enforces-final-crypto-move.htm"},{"credibility":2,"name":"Claw Wallet Launches to Shield On-Chain Assets for AI Agents - PR Newswire","type":"official","url":"https://www.prnewswire.com/news-releases/claw-wallet-launches-to-shield-on-chain-assets-for-ai-agents-302732600.html"},{"credibility":1,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments - SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"credibility":2,"name":"Active Exploitation Alert: Indirect Prompt Injection Attacks Target AI Agents - Rescana","type":"research","url":"https://www.rescana.com/post/active-exploitation-alert-indirect-prompt-injection-attacks-target-ai-agents-to-facilitate-unauthorized-cryptocurrency-p"}]}],"sources_used":[{"credibility":1,"name":"AI Prompt Injection Exploit Drains Grok-Linked Crypto Wallet - OECD.AI Incident Database","type":"other","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"credibility":1,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments - SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"credibility":1,"name":"Crypto platform Step Finance shutting down after $40 million theft - The Record","type":"news_article","url":"https://therecord.media/step-finance-cryptocurrency-theft-shutdown"},{"credibility":2,"name":"OWASP 2026 LLM Top 10 Released - Help Net Security","type":"research","url":"https://www.helpnetsecurity.com/2026/08/06/owasp-2026-llm-top-10-released/"},{"credibility":2,"name":"Prompt Injection tops 2026 OWASP GenAI / LLM Top Ten - SD Times","type":"research","url":"https://sdtimes.com/security/prompt-injection-tops-2026-owasp-genai-llm-top-ten-vulnerabilities/"},{"credibility":2,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says - The Block","type":"news_article","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"credibility":2,"name":"Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"},{"credibility":2,"name":"AI Trading Agent Vulnerability 2026: $45M Crypto Security Breach - KuCoin","type":"research","url":"https://www.kucoin.com/blog/en-ai-trading-agent-vulnerability-2026-how-a-45m-crypto-security-breach-exposed-protocol-risks"},{"credibility":2,"name":"OpenClaw AI Agent Incident Causes Millions in User Losses - KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/openclaw-ai-agent-incident-causes-millions-in-user-losses"},{"credibility":2,"name":"OpenClaw's Rampage Over Four Months Has Caused Users Millions in Losses - TechFlowPost","type":"news_article","url":"https://www.techflowpost.com/en-US/article/30957"},{"credibility":2,"name":"How Grok got prompt-injected: an X user drained $150,000 from an AI wallet - Giskard","type":"research","url":"https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet"},{"credibility":2,"name":"Prompt Injection Attack Drains $155,000 from Grok-Linked Bankr Crypto Wallet - BeyondMachines","type":"news_article","url":"https://beyondmachines.net/event_details/prompt-injection-attack-drains-155000-from-grok-linked-bankr-crypto-wallet-x-q-p-c-p"},{"credibility":2,"name":"Hackers Use Morse Code to Trick Grok and Bankrbot - GBHackers","type":"news_article","url":"https://gbhackers.com/hackers-use-morse-code-to-trick-grok-and-bankrbot/"},{"credibility":2,"name":"Grok Bankr Wallet Exploit: Free NFT Triggered $174K Loss - The Bit Journal","type":"news_article","url":"https://thebitjournal.com/grok-bankr-wallet-exploit-shows-how-a-free-nft-triggered-a-174k-ai-crypto-loss/"},{"credibility":2,"name":"Morse code used to bypass AI guardrails in $174,000 Grok-linked token theft on Base - Newsorga","type":"news_article","url":"https://newsorga.com/article/grok-bankrbot-morse-code-prompt-injection-174k-drb-theft-base-may-2026"},{"credibility":2,"name":"The Grok Morse Code Heist: When Prompt Injection Meets Excessive Agency - NeuralTrust","type":"research","url":"https://neuraltrust.ai/blog/grok-morse-code"},{"credibility":2,"name":"Active Exploitation Alert: Indirect Prompt Injection Attacks Target AI Agents - Rescana","type":"research","url":"https://www.rescana.com/post/active-exploitation-alert-indirect-prompt-injection-attacks-target-ai-agents-to-facilitate-unauthorized-cryptocurrency-p"},{"credibility":2,"name":"Malicious websites trick AI agents into crypto payments - SC Media","type":"news_article","url":"https://www.scworld.com/news/malicious-websites-trick-ai-agents-into-crypto-payments-context-poisoning"},{"credibility":2,"name":"Indirect Prompt Injection in Web Content Targets AI Agents - Infosecurity Magazine","type":"news_article","url":"https://www.infosecurity-magazine.com/news/indirect-prompt-injection-web/"},{"credibility":2,"name":"Hackers Abuse SEO Poisoning and Hidden HTML to Trick AI Agents - CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/hackers-abuse-seo-poisoning-and-hidden-html/"},{"credibility":2,"name":"Emerging Threat: AI Agent Poisoning via SEO and Hidden HTML - Threat-Modeling.com","type":"research","url":"https://threat-modeling.com/ai-agent-poisoning-seo-hidden-html-prompt-injection-july-2026/"},{"credibility":2,"name":"Hidden Webpage Instructions Are Making AI Agents Pay Hackers in Live Campaigns - TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/320039/20260709/hidden-webpage-instructions-are-making-ai-agents-pay-hackers-live-campaigns.htm"},{"credibility":2,"name":"$40 million worth of crypto stolen from Step Finance - Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/40-million-worth-crypto-stolen-110000837.html"},{"credibility":2,"name":"Step Finance Hack: $40M Solana Treasury Breach Explained - Panosnet","type":"news_article","url":"https://www.panosnet.com/step-finance-hack-40m-solana-treasury-breach-explained-2026/"},{"credibility":2,"name":"Prompt injection still drives most agentic AI security failures in production - Help Net Security","type":"research","url":"https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/"},{"credibility":2,"name":"Ledger Launches Agent Stack: AI Proposes, Hardware Enforces - TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/320757/20260716/ledger-launches-agent-stack-ai-proposes-hardware-enforces-final-crypto-move.htm"},{"credibility":2,"name":"Claw Wallet Launches to Shield On-Chain Assets for AI Agents - PR Newswire","type":"official","url":"https://www.prnewswire.com/news-releases/claw-wallet-launches-to-shield-on-chain-assets-for-ai-agents-302732600.html"},{"credibility":2,"name":"212 Crypto Exploits Stole $1.1B in H1 2026: Blockaid Report Breakdown - Thirdweb Blog","type":"research","url":"https://blog.thirdweb.com/cryptos-bloodiest-half-year-212-exploits-stole-1-1b-as-ai-powered-attacks-go-mainstream/"},{"credibility":2,"name":"OpenClaw Bot Gave Away $250K - Why Solana AI Agents Need Code-Level Permissions - Solana Compass","type":"research","url":"https://solanacompass.com/skills/agent-security"},{"credibility":2,"name":"5 Real AI Agent Security Breaches in 2026 and Their Lessons - Beam AI","type":"research","url":"https://beam.ai/agentic-insights/ai-agent-security-breaches-2026-lessons"},{"credibility":3,"name":"GitHub: Curated timeline of AI agent security incidents 2024-2026 - webpro255/awesome-ai-agent-attacks","type":"community_report","url":"https://github.com/webpro255/awesome-ai-agent-attacks"},{"credibility":3,"name":"AI Agent Security Risks 2026: MCP, OpenClaw and Supply Chain - CyberDesserts Blog","type":"research","url":"https://blog.cyberdesserts.com/ai-agent-security-risks/"}],"summary":"Prompt injection attacks against autonomous AI crypto trading agents constitute a documented and accelerating threat class in 2026, responsible for over $45 million in aggregate losses across multiple confirmed incidents. Attackers embed hidden instructions in airdropped NFT metadata, web page content, and encoded social media posts to cause AI agents with wallet signing authority to execute unauthorized fund transfers — no smart contract vulnerability required. Security firm Blockaid, OWASP, and researchers at Zscaler have each independently confirmed prompt injection as a live, reproducible attack vector against production AI agent deployments.","timeline":[{"date":"2026-01-31","event":"Step Finance suffers $40 million treasury breach on Solana. Attacker compromises executive devices and exploits overpermissioned AI trading agents to move approximately 261,000 SOL without human authorization. Only $4.7 million recovered. Platform subsequently shuts down.","source":"The Record (Recorded Future News)","source_url":"https://therecord.media/step-finance-cryptocurrency-theft-shutdown"},{"date":"2026-02-01","event":"OpenClaw AI agent 'Lobstar Wilde' transfers 52.43 million LOBSTAR tokens (valued at approximately $250,000) to an unintended address due to a quantity-parsing error. Tokens liquidated within 15 minutes for approximately $40,000. Malicious actors subsequently replicate the parsing logic to exploit other OpenClaw-based agents.","source":"KuCoin Flash News","source_url":"https://www.kucoin.com/news/flash/openclaw-ai-agent-incident-causes-millions-in-user-losses"},{"date":"2026-05-04","event":"Bankr/Grok prompt injection attack on Base chain. Attacker airdrops a 'Bankr Club Membership' NFT to Grok's wallet to escalate permissions, then posts a Morse-code-encoded transfer instruction on X. Grok decodes the message; Bankr executes the transfer. Approximately 3 billion DRB tokens ($155,000-$175,000) are drained. Around 80% recovered after community doxxing.","source":"OECD.AI Incident Database","source_url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"date":"2026-06-11","event":"OWASP publishes findings that prompt injection drives most agentic AI security failures in production. Help Net Security reports prompt injection attacks surged 340% in 2026.","source":"Help Net Security","source_url":"https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/"},{"date":"2026-07-06","event":"SecurityWeek reports Zscaler's discovery of two active indirect prompt injection campaigns using SEO poisoning and hidden HTML to make AI agents transfer cryptocurrency to attacker-controlled wallets. Testing confirms four of 26 LLMs execute unauthorized payments after reading a malicious webpage.","source":"SecurityWeek","source_url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"date":"2026-07-09","event":"TechTimes covers active campaign in which hidden webpage instructions are confirmed to be causing AI agents to pay hackers in live deployments, corroborating Zscaler findings.","source":"TechTimes","source_url":"https://www.techtimes.com/articles/320039/20260709/hidden-webpage-instructions-are-making-ai-agents-pay-hackers-live-campaigns.htm"},{"date":"2026-07-16","event":"Ledger announces Agent Stack, a hardware-enforced human-in-the-loop signing architecture for AI crypto agents, directly referencing the prompt injection threat class as motivation.","source":"TechTimes","source_url":"https://www.techtimes.com/articles/320757/20260716/ledger-launches-agent-stack-ai-proposes-hardware-enforces-final-crypto-move.htm"},{"date":"2026-07-29","event":"Blockaid publishes H1 2026 security report documenting 212 on-chain exploits totaling $1.1 billion — a record — and identifying AI agent prompt injection as an emerging and growing attack sub-category. Blockaid projects AI agent deployments growing 10x annually and forecasts multiple additional AI agent incidents in H2 2026.","source":"The Block","source_url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"date":"2026-08-06","event":"OWASP releases 2026 LLM Top 10. Prompt injection retains the number-one position for the third consecutive year. Excessive agency rises to third place. For the first time, rankings incorporate real-world incident data from 6,639 documented incidents.","source":"Help Net Security","source_url":"https://www.helpnetsecurity.com/2026/08/06/owasp-2026-llm-top-10-released/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 4d41a802-aee4-4af4-914b-ca0c9215013a
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.