All incidents
High
44B · Incident

How Grok got prompt-injected: an X user drained $150,000 from an AI wallet

Date
July 22, 2026
Category
LLM
Source
AI Incident Database

Summary

A X user sent a morse code message tricking Grok into authorizing a $150,000 crypto transfer. This is a prompt injection attack against an autonomous AI agent. In this article we explain how an input obfuscation allowed the heist to occur, ... (https://incidentdatabase.ai/cite/1556#7549)

Large developers must disclose safety incidents to the Attorney General within 72 hours of discovery under Art. 44-B § 1422 — 24 hours where there is an imminent risk of death or serious physical injury.

File an incident report →