Token Metadata Can Trigger Prompt Injections in AI Trading Agents
Embedded text may prompt token purchases, asset transfers or unlimited authorizations. About $215,000 tied to a Bankr-related wallet was transferred in May.

Token metadata can expose AI trading agents to prompt injections that trigger token purchases, asset transfers or unlimited authorizations when the agents read embedded text as instructions.
Attackers are placing harmful prompts in token names, symbols and descriptions. When an AI trading agent incorporates that text into its context, the embedded content may influence the action it takes.
About $215,000 in assets tied to a Bankr-related AI agent wallet were transferred in May after the wallet was exposed to prompts on social media. A separate security research demonstration showed that a malicious token description could induce an agent to execute an unlimited token authorization.
The recommended safeguard is to simulate and validate the exact transaction immediately before signing. The recommendation is intended to reduce the risk of prompt-injection attacks.


