The cryptocurrency ecosystem has long been familiar with exchange hacks, bridge exploits, and wallet drains. But a new category of threat emerged on March 19, 2025, when attackers demonstrated that the decision-making logic of an autonomous AI agent can itself become the exploitable surface — no stolen credentials, no infrastructure breach, just carefully crafted inputs that tricked an AI into signing away its own funds.
The target was AiXBT, a popular AI-driven crypto market commentator built on the Virtuals Protocol with nearly half a million followers on social media. An attacker operating under a now-deleted account called “FungusMan” gained access to the autonomous system dashboard and queued two malicious reply prompts that instructed the agent to transfer 55.5 ETH, approximately $106,200 at prevailing market prices, to attacker-controlled addresses. The incident sent the AIXBT token plunging nearly 20% to $0.0938 within 24 hours, while the broader crypto market traded higher with Bitcoin at $86,854 and Ethereum at $2,057.
The Exploit Mechanics
The attack unfolded in a way that confounds traditional cybersecurity frameworks. At approximately 2:00 AM UTC on March 18, the attacker accessed AiXBT’s secure management dashboard. Rather than attempting to extract private keys or compromise wallet infrastructure, the hacker queued what amounted to social engineering prompts directed at the AI agent itself. These prompts framed unauthorized transfers as routine operational behavior.
Because AiXBT was designed to process external signals and social inputs as part of its autonomous market commentary system, it interpreted the malicious inputs as legitimate instructions. The agent’s Simulacrum wallet — a mechanism that enables on-chain actions triggered by social media posts — executed two separate transfers to the attacker’s address. Each transfer was signed and broadcast on-chain before any human operator could intervene.
The pseudonymous developer behind AiXBT, known as rxbt, confirmed that the exploit did not compromise core systems or represent a failure of the underlying AI model. The vulnerability lay in the feedback loop: the agent had the authority to execute financial transactions autonomously based on inputs it received, without adequate validation or human-in-the-loop confirmation for high-value actions.
Affected Systems
The direct financial impact was contained to AiXBT’s Simulacrum wallet, with 55.5 ETH drained. However, the ripple effects extended well beyond the immediate loss. The AIXBT token, which trades on the Base network, experienced a sharp decline of approximately 16-20%, erasing millions in market capitalization. At the time of the breach, AiXBT’s market cap stood at roughly $82.4 million, down significantly from its January 2025 peak of $755 million.
The broader AI agent token sector also felt the impact. Confidence in autonomous trading platforms and AI-driven financial instruments took a measurable hit, with several competing AI agent tokens posting declines in the days following the breach. The incident raised uncomfortable questions about the security posture of the rapidly growing AI agent economy, which encompasses dozens of platforms and billions in combined market capitalization.
Users of the AiXBT Terminal, a premium market intelligence platform accessible by holding AIXBT tokens, faced uncertainty about whether the data and recommendations provided by a compromised agent could be trusted. The platform’s reputation as a reliable market commentator was temporarily undermined, even though core systems remained intact.
The Mitigation Strategy
The AiXBT team responded swiftly to the breach. Within hours, they had reported the attacker’s wallet address to major centralized exchanges, increasing the likelihood that any attempt to cash out the stolen ETH would be flagged and frozen. Access keys were rotated across all systems, and the team initiated a complete server migration to eliminate any potential backdoor access the attacker may have established.
AiXBT itself acknowledged the incident on social media, stating: “Simu wallet was cooked, but core systems unaffected. If you’re trading AIXBT, this doesn’t change fundamentals. Expect improved security after server migration.” The statement was calibrated to reassure token holders while acknowledging the seriousness of the breach.
Looking forward, the incident has catalyzed a broader conversation within the AI agent development community about the need for multi-signature authorization on high-value transactions, rate limiting on agent-initiated transfers, and anomaly detection systems that can flag unusual transaction patterns before they are executed on-chain.
Lessons Learned
The AiXBT breach introduces a paradigm that traditional security teams are ill-equipped to handle: behavioral manipulation of autonomous systems. Unlike credential theft or infrastructure exploitation, this attack vector targets the decision-making process of the AI itself. When an agent has both the authority to interpret external inputs and the capability to execute irreversible financial transactions, the attack surface expands dramatically.
Key lessons from this incident include: First, autonomous agents should never have unilateral authority to execute high-value transactions without secondary validation. Second, input validation for AI agents must be treated with the same rigor as input validation for web applications and smart contracts. Third, real-time monitoring of agent behavior should include anomaly detection for unusual transaction patterns, unexpected recipient addresses, or sudden changes in transaction frequency.
The crypto industry has learned hard lessons about smart contract security, bridge design, and private key management. The AiXBT incident suggests that AI agent security will be the next frontier — and that the stakes are just as high.
User Action Required
For users of AI-driven trading platforms and autonomous agents, the AiXBT incident should serve as a wake-up call. Review the permission structures of any AI agent that has access to your wallets or funds. Ensure that spending limits, withdrawal whitelists, and multi-step approval processes are enabled wherever possible. Monitor agent activity regularly, and do not assume that because an agent is powered by advanced AI, it is immune to manipulation.
For developers building autonomous AI agents, implement behavioral guardrails from day one: transaction limits, cooldown periods for large transfers, human-in-the-loop confirmation for actions above a certain threshold, and continuous monitoring for anomalous behavior patterns. The technology enabling AI agents is powerful, but without robust security frameworks, that power becomes a liability.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making investment decisions.
55.5 ETH gone because someone typed the right words at an AI. this is the wildest attack vector ive seen in crypto
prompt injection is a known attack vector in AI research. applying it to autonomous financial agents was inevitable. the scary part is how easy it was
prompt injection has been in the OWASP top 10 for LLMs since day one. a financial agent without input sanitization is negligence not innovation
not even the right words. just a queued reply prompt through a dashboard. no social engineering required, just access to the admin panel
The fact that FungusMan got in through the dashboard and not through a key compromise is what worries me. How many other AI agents have weak access controls on their admin panels?
right, the exploit wasnt even that sophisticated. just queued malicious prompts through a dashboard. if this is the state of AI agent security we are in serious trouble
virtuals protocol has dozens of AI agents running and most probably have similar access control gaps. aixbt was just the first to get targeted because it had the biggest wallet
every AI agent running on virtuals is checking their dashboard access controls today. if FungusMan got in that easy someone else will try next week
Marcus Webb the scary part is most AI agent dashboards still have no MFA in 2026. FungusMan was just the first to try
500K followers and six figure tx capability behind a dashboard login with no MFA. the security gap between AI agent capability and agent protection is enormous
a 20% dump on the token because the agent got socially engineered. imagine what happens when AI agents manage actual DAO treasuries. we need hardware-level signing controls not dashboard passwords
null_ptr_ HSM signing for agent transactions should be table stakes by now. the fact that a dashboard prompt can authorize a 55 ETH transfer means nobody learned from the wallet approval bugs of 2021
55.5 ETH stolen from an AI agent with 500K followers and the token dumped 20%. the attacker probably made more shorting AIXBT than from the actual ETH theft
$106k from the theft itself but AIXBT token dropped 20%. the attacker definitely shorted on perps before triggering the prompts. the real exploit was the short position not the ETH drain
Asha B. the short theory makes the most sense. you dont steal 55 ETH from an AI agent unless you already positioned for the token dump. the theft was the trigger not the payday
Asha B. the 20% AIXBT dump was the actual profit center. 55.5 ETH is gas money compared to what a well timed short on the token makes. the theft was the announcement not the trade
Wei C. the 55 ETH heist was the trigger not the payday. short AIXBT on perps, queue the malicious prompts, dump the token 20%, profit on the short. classic
the dashboard had no 2FA on queued prompts. you could literally just log in and type instructions. for a system managing a half million follower account that is wild negligence
dashboard_auth_ no rate limiting on queued prompts for a system managing real funds is criminal negligence not a learning moment
dashboard_auth_ no rate limiting either. FungusMan queued multiple malicious prompts and not a single one triggered a review. the guardrails were nonexistent
Yuki I. no 2FA AND no rate limiting on queued prompts. at that point you are basically running an open endpoint. any script kiddie could have done this
dashboard_auth_ no 2FA AND no rate limiting on queued prompts. at that point you are basically running an open endpoint. any script kiddie could have done this
multisig_mike_ no rate limiting on prompts managing 6 figure txs. SOC2 auditors would have a field day with that finding
soc2_rat_ AIXBT dumping 20% because someone queued two malicious replies into the dashboard. zero authentication on the prompt queue is an industry-wide problem nobody talks about
This covers the key points effectively. Good work!
tricking an AI agent into signing away 55.5 ETH with just crafted prompts is terrifying. the attack surface isnt the smart contract anymore, its the LLM decision layer