BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home NFT

Someone Sent Grok a Free NFT and Walked Away With $174K — Here’s the Playbook

Michael Juanico by Michael Juanico
May 14, 2026
in NFT, OPINION
Share on XShare in TelegramShare on Reddit
  • An attacker used a free NFT and Morse code to drain roughly $174,000 from Grok’s wallet
  • The NFT silently upgraded wallet permissions, allowing token transfers and swaps
  • Researchers say the exploit exposed major weaknesses in autonomous AI wallet systems

What looked like a harmless NFT transfer turned into one of the stranger crypto exploits of the year. An attacker managed to drain roughly $174,000 worth of DRB tokens from Grok’s Bankr-connected wallet on Base, not by hacking through security barriers, but by giving the wallet new permissions through a free NFT.

The attacker essentially handed Grok a key, waited for the system to accept it, and then manipulated the AI into opening the door itself. Weirdly enough, no direct wallet compromise was needed at all.

The NFT That Quietly Changed Everything

The exploit started when the attacker sent Grok a Bankr Club Membership NFT on the Base network. On the surface, it looked like just another token transfer, but underneath, the NFT acted more like a permission upgrade than a collectible.

Once the wallet held the NFT, Bankr automatically expanded the wallet’s capabilities, enabling real token transfers, swaps, and deeper interaction with Bankr’s infrastructure. Before receiving the NFT, Grok’s wallet had limited functionality. After receiving it, the wallet could suddenly move funds freely.

That’s the part making security researchers uncomfortable right now. The attacker didn’t bypass protections, they used the system exactly as designed.

Morse Code Became the Trigger

After upgrading the wallet’s permissions, the attacker took things a step further using something almost absurdly simple, Morse code. Beneath one of Grok’s public posts, the attacker replied with encoded instructions that translated into a command directing @bankrbot to send tokens to a specific wallet address.

Grok, designed to interpret and assist users, translated the Morse code into plain English and publicly tagged Bankrbot in the process. Since the request appeared authenticated and legitimate, Bankrbot executed the command automatically.

That single interaction transferred roughly 3 billion DRB tokens, representing around 3% of the token’s supply and valued near $175,000 at the time. The token price collapsed roughly 40% within minutes after the transfer became visible on-chain.

Researchers Say This Wasn’t Really a “Grok Hack”

Security researchers quickly pointed out that the issue may have less to do with Grok itself and more to do with Bankr’s infrastructure design. According to Vadim, a former NEAR core contributor, the real weakness came from how Bankr automatically provisions wallets and permissions for every connected X account, including AI agents.

That architecture created an environment where receiving an NFT could silently alter what an AI-controlled wallet was capable of doing. Following the incident, Bankr introduced optional IP whitelisting, permission-based API controls, and settings allowing users to disable actions triggered through X replies.

Those fixes arrived after the exploit, though, which feels a little like locking the door after the house already got cleaned out.

AI Wallets Are Becoming a New Security Nightmare

The bigger concern now is what this attack pattern represents moving forward. The exploit introduced a new kind of privilege escalation where simply gifting an NFT or airdrop can expand an AI agent’s operational permissions without explicit approval from a human operator.

For autonomous AI systems connected to wallets, that’s a serious problem. Attackers may no longer need to steal keys directly if they can instead manipulate the AI into voluntarily using its own tools against itself.

AI agents with live crypto wallets were supposed to represent the future of automation and digital finance. But right now, security systems around them seem to be evolving much slower than the creativity of the people trying to exploit them.

Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.
Tags: AIcryptoGROKNFTsecurity
TweetShareShare
Michael Juanico

Michael Juanico

Michael is a BSBA Management graduate from Mindanao State University and has been a professional content writer since 2019. He began exploring cryptocurrency in 2021 and has since made blockchain and digital assets his primary focus. For nearly four years, Michael has contributed research and editorial content at Aiur Labs and BlockNews, producing clear and accessible coverage of market trends, trading strategies, and project developments. He is transparent about his personal holdings in Bitcoin, TRON, and select meme tokens, combining writing expertise with hands-on market experience to deliver trustworthy insights to readers.

DON'T MISS THESE! HOT OFF THE PRESS

Bitcoin ETFs Just Had Their Worst Day in Months — Blame the Fed (Again)
BITCOIN

Bitcoin ETFs Just Had Their Worst Day in Months — Blame the Fed (Again)

May 14, 2026
Coinbase Just Took Over Hyperliquid’s Stablecoin Layer – Here Is Why That Matters
CRYPTO

Coinbase Just Took Over Hyperliquid’s Stablecoin Layer – Here Is Why That Matters

May 14, 2026
Jamie Dimon’s Bank Just Bought More Bitcoin Than His Mouth Said It Would
BITCOIN

Jamie Dimon’s Bank Just Bought More Bitcoin Than His Mouth Said It Would

May 14, 2026
Solana Slips Back to $90 After $100 Rejection – Here Is What Spooked The Market
CRYPTO

Solana Slips Back to $90 After $100 Rejection – Here Is What Spooked The Market

May 14, 2026
Bank of England Is Backtracking on Stablecoins – Here Is Why Crypto Firms Forced a Rethink
CRYPTO

Bank of England Is Backtracking on Stablecoins – Here Is Why Crypto Firms Forced a Rethink

May 14, 2026
Metaplanet Lost $725 Million on Paper in Q1 While Actually Making a Killing
BITCOIN

Metaplanet Lost $725 Million on Paper in Q1 While Actually Making a Killing

May 13, 2026
Load More

Related News

Someone Sent Grok a Free NFT and Walked Away With $174K — Here’s the Playbook

Someone Sent Grok a Free NFT and Walked Away With $174K — Here’s the Playbook

May 14, 2026
Bitcoin ETFs Just Had Their Worst Day in Months — Blame the Fed (Again)

Bitcoin ETFs Just Had Their Worst Day in Months — Blame the Fed (Again)

May 14, 2026
Coinbase Just Took Over Hyperliquid’s Stablecoin Layer – Here Is Why That Matters

Coinbase Just Took Over Hyperliquid’s Stablecoin Layer – Here Is Why That Matters

May 14, 2026
Jamie Dimon’s Bank Just Bought More Bitcoin Than His Mouth Said It Would

Jamie Dimon’s Bank Just Bought More Bitcoin Than His Mouth Said It Would

May 14, 2026
Solana Slips Back to $90 After $100 Rejection – Here Is What Spooked The Market

Solana Slips Back to $90 After $100 Rejection – Here Is What Spooked The Market

May 14, 2026
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About Us
  • Contact Us
  • Editorial Policies
  • Terms and Conditions
  • Privacy Policy
  • Sitemap

DISCLOSURES AND POLICIES

BlockNews provides independent reporting on crypto, blockchain, and digital finance. Content is for informational purposes only and does not constitute financial advice. Sponsored material is always disclosed. By using this site, you agree to our Terms and Conditions and Privacy Policy.

© 2025 BlockNews

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews