Grok agent loses up to $200K after Morse code goal hijack
Attackers posted Morse code strings and obfuscated Python snippets on X that Grok's AI agent interpreted as a legitimate instruction. The connected trading bot Bankr executed a crypto transfer of $150,000–$200,000 without verifying the instruction's source.
- Losses estimated at $150,000–$200,000 in crypto
- Attack used Morse code and split Python strings to evade filters
- Bankr executed the transfer without verifying the operator's identity
- Incident classified as OWASP ASI01: Agent Goal Hijack
Read next
Security