Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › AI agent scams

AI agent crypto scams: when the software moves your money

By Golan Ben Moshe · Co-founder, Chain Pursuit · 10 min · Last updated 1 October 2026

An AI agent is software that can take actions rather than only answer questions. Connect one to a wallet and anything it reads can potentially instruct it, including content written by a stranger. In May 2026 an attacker took between $150,000 and $200,000 from a wallet linked to an AI agent using nothing but a public post. No private key was stolen. No smart contract was exploited.

Who this is for

Anyone considering an AI trading bot or agent wallet. Anyone who has already connected one. And anyone who has lost money to something marketed as artificial intelligence, which is an increasingly crowded category.

The FBI's Internet Crime Complaint Center recorded $11.37 billion in cryptocurrency fraud losses reported by US victims in 2025, from 181,565 complaints. Average reported loss was $62,604, victims aged 60 and over reported the largest share, and the FBI named AI-enabled deception among the drivers.

The theft where nobody stole a key

On 4 May 2026, an attacker took roughly 3 billion DRB tokens, worth between $150,000 and $200,000 at the time, from a wallet on the Base network. The method is worth understanding in full, because it is not like anything that came before it.

The wallet belonged to an AI agent. Bankr is a crypto trading agent operating on X that automatically creates a linked wallet for accounts it interacts with, including the one belonging to Grok, xAI's chatbot.

First, the attacker expanded the wallet's permissions. They sent it a Bankr Club Membership NFT. Holding that token moved the wallet from read-only to transaction execution.

Then they posted a public reply containing an instruction encoded in Morse code, and asked Grok to decode it. Grok decoded the message, in public, as it had been asked to.

Bankr's agent read the decoded text as an authorised instruction and sent the money.

No key was stolen. No contract was exploited. No phishing link was clicked. The incident is logged in the OECD's AI Incidents Monitor, and the mechanism generalises to every agent that reads content other people can write.

How the May 2026 agent wallet drain worked
NFT arrivespermissions widenPublic postinstruction, encodedAI decodes itin public, as askedBot actstreats it as authorityNo key was stolen. The failure is at step four, where a machine's output crossed into authority.
Four steps, none of which involved stealing a key. The last one is where a machine's output crossed into authority it should never have had.

What an AI agent is

The word "agent" is doing real work here, and it is worth separating from the chatbot most people have used.

A chatbot answers. You ask a question, it produces text. If it is wrong, you have been misinformed and nothing else has happened.

An agent acts. It sends transactions, calls services, moves funds, books things, writes to systems. If it is wrong, or if it has been misled, something has happened that may not be reversible.

The security risk sits entirely in that difference. A chatbot that is manipulated tells you something false. An agent that is manipulated does something real.

"Autonomous" is the word to be suspicious of in marketing copy. It means the software acts without asking you first, which is presented as convenience and is also the removal of the last checkpoint between an instruction and your money.

Why anything an agent reads can instruct it

This is the part that surprises people, including people who build these systems.

An AI model does not reliably distinguish between instructions from its operator and content it has been given to read. If it is processing a web page, a document, a message or a public reply, and that content contains something shaped like an instruction, the model may follow it.

Security researchers call this prompt injection. It has been recognised since large language models became widely available, and it remains unsolved rather than merely unfixed.

The Grok case illustrates why filters do not close it. The instruction was encoded, so it did not look like an instruction to any filter watching for one. Encode it differently next time and the filter misses again. Every fix addresses the specific attack that prompted it, which means the fix arrives one exploit late.

What this means for you, stripped of the vocabulary: if an agent with access to your wallet reads anything written by someone else, that person has a channel to it.

The four ways this reaches an ordinary person

1. The "AI agent" that is malware

The most common version, and it requires no understanding of agents at all.

Between April and June 2026, HP's threat researchers tracked a campaign that built a website for a fake AI crypto trading agent, gave the product a name echoing a well-known AI assistant, and promised automated trading around the clock. Victims arrived through search results and advertisements.

The download delivered malware called Needle Stealer, which replaces your browser wallet extension with a counterfeit copy that sends your wallet password to the attacker. Seven extensions were targeted, including MetaMask, Coinbase Wallet and Phantom.

One detail explains why "my security software did not warn me" is not reassurance. The file inside the download, named to look like the trading agent, was in fact a legitimate Microsoft-signed Windows program being abused as a launcher. Windows SmartScreen's reputation check trusted it, because the reputation was real.

2. The genuine agent with more permission than it deserves

The Grok case. The agent was real, the platform was real, and the loss happened because the wallet's permissions were expanded and nothing capped what a single instruction could move.

The scale of the theft had nothing to do with the sophistication of the attack. It was $200,000 rather than $20 because no limit existed.

3. The agent whose tools were tampered with

This is where MCP comes in, and it is the layer furthest from you that can still reach your wallet.

In February 2026 an established malware operation spent around three months constructing a fake developer ecosystem: five fake GitHub accounts with AI-generated personas, cross-forked to look like an active community, with fabricated contributors and the genuine author excluded. It then submitted a trojanized version of a legitimate MCP server to a real registry, functionally identical to the original.

The payload harvested browser passwords, cloud session tokens, SSH keys, API keys and cryptocurrency wallet files, while disguising its persistence as a Windows audio process.

The target there was developers rather than ordinary holders, and it is in this article for one reason: the software your wallet touches has its own supply chain, and you cannot inspect it.

4. The "AI-powered recovery service"

The oldest fraud in this space, rebranded.

After a loss, people are contacted by services promising to trace and return funds for a fee, and that promise is increasingly dressed in AI language: proprietary models, automated tracing, machine learning that recovers what humans cannot.

The technology described does not change what is possible. A private key cannot be derived from a public address. Confirmed transactions on a public blockchain cannot be reversed by any private company. Adding "AI" to those claims makes them newer, not truer.

Our guide to spotting a recovery scam covers the questions to ask, and they are unchanged by the branding.

What MCP is, and why you keep seeing it

MCP stands for Model Context Protocol. It is an open standard, introduced by Anthropic in late 2024, that defines how AI systems connect to external tools and data: file access, web search, database queries, API calls.

It is not a coin. It is not a wallet. There is nothing to buy. If someone is selling you an MCP token or an MCP wallet, that is the scam, complete, with no further investigation required.

It matters here because it is the layer an agent uses to reach other systems, including anything holding your money. Malicious MCP servers have been published to legitimate registries, as above. OWASP now maintains an MCP Top 10 listing the risks, with credential exposure and tool poisoning among the leading entries, which tells you the industry considers this an open problem rather than a solved one.

For an individual the practical takeaway is short: you will not audit this layer, so reduce what it can reach.

Before you connect an agent to a wallet

Red flags

What to do if an agent has already moved your funds

Revoke its access first, then move remaining assets to a wallet the agent has never touched. If the agent held keys directly rather than permissions, treat the wallet as compromised and follow our guide to a compromised wallet.

Preserve the evidence before accounts disappear. Transaction hashes, the agent platform, the instruction or content that triggered it if you can find it, and any account you used. Our evidence checklist covers what matters.

Report it. Our country guides explain which channel in your jurisdiction can open an investigation rather than only collecting intelligence.

Contact the platform. Where an agent platform's own failure caused the loss, it may have a process. In the May 2026 case the platform suspended transactions and reporting indicates a portion of the funds was later returned, though the circumstances there were unusual and public attention played a part.

Expect an approach afterwards from someone offering to recover the funds, quite possibly describing their method as AI-driven.

What this guide cannot do

Agent wallet security is immature and the documented incidents are recent. Nothing here makes connecting an agent to a wallet safe, and no product mentioned or unmentioned should be read as endorsed. Reducing what an agent can reach is the only control that reliably works, and it limits damage rather than preventing it.

This is general information, not legal, financial or technical security advice.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Sources

OECD AI Incidents Monitor, AI Prompt Injection Exploit Drains Grok-Linked Crypto Wallet, May 2026. https://oecd.ai/en/incidents/2026-05-04-4a73

CCN, AI Agent Drained for $200K With This One Tweet Hack, 5 May 2026. https://www.ccn.com/news/crypto/ai-agent-drained-for-200k-with-this-one-tweet-hack-heres-how/

Giskard, How Grok Got Prompt-Injected, July 2026. https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet

Help Net Security, Fake AI trading agent steals crypto wallet passwords, 17 September 2026. https://www.helpnetsecurity.com/2026/09/17/fake-ai-trading-agent-research/

The Hacker News, SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer, February 2026. https://thehackernews.com/2026/02/smartloader-attack-uses-trojanized-oura.html

OWASP Foundation, OWASP MCP Top 10. https://owasp.org/www-project-mcp-top-10/

Valuations for the May 2026 incident range from approximately $150,000 to $200,000 depending on the source and the moment of valuation. Reporting that around 80% of the funds were later returned is widely repeated but not confirmed by a primary source. IC3 figures are as reported in secondary coverage of the 2025 annual report.

Frequently asked questions

Can an AI steal my cryptocurrency on its own?

Not in the sense of deciding to. What has happened is that AI agents connected to wallets have been manipulated by people into moving funds. The agent is the instrument rather than the attacker, and the result for you is identical.

What is prompt injection, in plain terms?

An AI model does not reliably tell the difference between instructions from its operator and content it has been given to read. If someone hides an instruction in a web page, message or post that the AI processes, it may follow it. When the AI can move money, that becomes a theft.

Is MCP a cryptocurrency?

No. MCP is the Model Context Protocol, an open standard introduced by Anthropic in late 2024 for connecting AI systems to tools and data. There is no MCP coin, token or wallet. Anything sold as one is fraudulent.

Are AI trading bots safe to use?

Security for this category is immature and the documented failures are recent. If you use one, connect it to a wallet holding only what you would accept losing, require approval for transfers, and assume any content it reads is a channel an attacker could use.

How did someone steal crypto with a tweet?

In May 2026 an attacker sent an NFT that expanded an agent wallet's permissions, then posted an instruction encoded in Morse code and asked the AI to decode it. A connected trading bot treated the decoded text as an authorised command and transferred the funds. No key was stolen and no smart contract was exploited.

My antivirus did not flag the AI trading app I downloaded. Does that mean it was safe?

Not necessarily. One 2026 campaign delivered its malware inside a legitimate Microsoft-signed Windows program used as a launcher, so reputation checks trusted it. A clean scan is one signal among several, not a verdict.

Can an AI service recover crypto I have already lost?

No more than a human service can, which in most cases means no. A private key cannot be derived from a public address, and confirmed blockchain transactions cannot be reversed by a private company. AI branding on that claim does not change what is possible.

What permissions should I give an AI agent that trades for me?

As few as the task requires, on a wallet funded only with what you would accept losing, with your approval required before any transfer. If the product cannot operate under those conditions, that tells you what it needs from you.

Has something already gone wrong?

Eleven questions showing which documentation and reporting routes are available in your case.

Check my case

Keep reading