Researchers drain OKX AI wallet with a single prompt via unsanitized token metadata

Researchers reported draining OKX's AI-powered wallet agent with a single prompt, because OnchainOS feeds unsanitized token descriptions from the search API directly into the agent's context, letting a malicious token description act as instructions. A Chinese KOL claimed the exploit, and the wallet was reportedly emptied from roughly 12,000 USDC to zero.

Detected & updated continuously · Source: Nebula

Story subjects

OKX WalletOKXOnchainOS

Track sentiment and mindshare across stocks and crypto in Nebula.

Open Nebula