Scammer STEALS $200K From AI Bots Using Morse Code…

A sophisticated scammer successfully manipulated two artificial intelligence systems into transferring $200,000 worth of cryptocurrency by hiding instructions in Morse code. The attack exposed critical security vulnerabilities in AI-enabled financial systems and demonstrated how social engineering techniques can bypass existing safeguards.

How the Attack Unfolded

The perpetrator targeted Grok, Elon Musk’s AI chatbot, and Bankrbot, an automated trading system with cryptocurrency wallet access. Operating under the handle @Ilhamrfliansyh, the attacker initiated the scheme by sending a Bankr Club Membership NFT to Grok’s wallet. This digital asset expanded Grok’s permissions within the Bankr ecosystem, granting it capabilities to perform token transfers and cryptocurrency swaps that were previously restricted. The account was deleted immediately after the transaction completed.

The Morse Code Deception

Once elevated permissions were established, the attacker prompted Grok to translate a message encoded in Morse code and relay the decoded content to Bankrbot. The translated message contained specific instructions commanding the bot to transfer 3 billion DRB tokens to a wallet address controlled by the attacker. The critical vulnerability was that the decoded message was automatically treated as legitimate. With no additional verification or human oversight, the instruction executed immediately on the Base blockchain network.

Market Impact and Aftermath

Following the unauthorized transfer, the perpetrator moved quickly to liquidate the stolen assets. The attacker immediately sold the DRB tokens on cryptocurrency exchanges, flooding the market with a large volume that caused the token’s price to tumble. The entire operation was executed through concealed instructions that successfully bypassed existing security safeguards. The incident highlights concerning weaknesses in AI-enabled financial systems and their susceptibility to creative manipulation techniques.

What This Means

This attack demonstrates that artificial intelligence systems with financial access remain vulnerable to social engineering despite their sophistication. The use of Morse code to hide malicious instructions reveals that security measures must account for encoding schemes that can slip past automated detection. As AI systems gain broader access to financial tools, developers face mounting pressure to implement verification protocols that prevent similar exploits. The incident serves as a warning about the risks of granting autonomous systems control over cryptocurrency transactions without adequate human oversight or multi-step authentication requirements.