Scammer Uses Morse Code to ROB AI Bots of $200K in Crypto

A cybercriminal successfully manipulated two artificial intelligence systems into transferring $200,000 worth of cryptocurrency by hiding instructions in Morse code, exposing critical vulnerabilities in AI-enabled financial platforms that operate without human oversight.

How the Digital Heist Unfolded

The attack targeted Grok, Elon Musk’s AI chatbot, and Bankrbot, an automated trading system with direct access to cryptocurrency wallets. Operating under the handle @Ilhamrfliansyh on X, the perpetrator first sent a Bankr Club Membership NFT to Grok’s wallet. This digital token expanded the AI’s permissions within the Bankr ecosystem, granting it new capabilities to execute token transfers and cryptocurrency swaps that were previously restricted.

Once elevated permissions were established, the attacker prompted Grok to translate a message written in Morse code and relay the decoded content to Bankrbot. The translated instruction commanded the bot to transfer 3 billion DRB tokens to a wallet address controlled by the criminal. With no verification system or human approval required, the bots automatically executed the command. The transaction processed on the Base blockchain network, completing the unauthorized transfer of assets valued at roughly $200,000.

The Aftermath and Market Impact

Following the successful theft, the perpetrator moved quickly to liquidate the stolen digital assets. The attacker immediately sold the DRB tokens on cryptocurrency exchanges, flooding the market with supply. This sudden volume caused the token’s price to plummet as buyers absorbed the massive sell-off. The user’s X account was deleted shortly after completing the transaction, eliminating direct accountability and making recovery efforts significantly more difficult.

What This Means for AI Security

This incident demonstrates alarming weaknesses in artificial intelligence systems granted access to financial accounts. The attack succeeded because decoded messages were automatically treated as legitimate commands without additional security layers. No verification protocols existed to confirm the authenticity of instructions, and no human oversight monitored the unusual transaction. As companies increasingly deploy AI systems with real-world financial authority, the Morse code exploit reveals how creative social engineering can bypass existing safeguards. Security experts warn that similar vulnerabilities likely exist across numerous AI-powered platforms handling valuable assets without adequate protective measures.