Musk says xAI will make you whole if Grok loses your money, but the fine print caps liability at $100.
The Summary
- A Morse code exploit in May triggered a six-figure crypto theft through Grok and a connected payment agent called Bankrbot
- Musk publicly promised users would be made whole if AI loses their money, but xAI's terms of service limit liability to $100
- The gap between promise and contract shows the accountability vacuum in agentic finance: who pays when an AI agent gets exploited?
The Signal
The May attack worked like this: someone embedded instructions in Morse code, fed them to Grok, which passed them to Bankrbot, a crypto payment agent with wallet access. The agent executed. Six figures gone. The exploit didn't require hacking a private key or breaking encryption. It just required understanding how connected AI systems pass instructions to each other.
This is the Web4 accountability problem in miniature. When your agent talks to my agent talks to a payment rail, and something goes wrong, who holds the bag?
"The attacker didn't break the system. They spoke its language."
Musk's public response was immediate and generous: xAI would make users whole. But the legal reality is different. The terms of service cap xAI's liability at $100. That's not a typo. That's standard liability-limiting language that every tech company uses. The gap between the tweet and the terms is where the real story sits.
Three ways this plays out:
- Musk honors the promise anyway, setting a precedent that promises override contracts in agentic finance
- xAI points to the TOS, users sue, and we get our first major case law on AI agent liability
- Nobody loses enough money yet for it to matter, and the problem compounds silently until it does
The Morse code vector is especially revealing. It suggests prompt injection attacks will evolve into multi-agent coordination attacks. You don't compromise Agent A directly. You send Agent A something that looks harmless but becomes instructions when Agent A talks to Agent B. The attack surface isn't the model anymore. It's the space between models.
Traditional finance solved this with layers of verification, settlement times, and reversal mechanisms. Web3 solved it with keys and signatures: not your keys, not your coins. Web4 is trying to solve it with agents that hold keys on your behalf. That requires a new model. Maybe it's insurance pools. Maybe it's bonded agents that stake collateral. Maybe it's multi-sig arrangements where your agent proposes and you approve.
The Implication
If you're building agents that touch money, the liability question isn't theoretical anymore. You need answers before the exploit, not after. And if you're Elon Musk making promises on Twitter that your TOS doesn't support, you're either about to cut a lot of checks or face a lot of lawsuits. The market will figure out which one faster than your lawyers will.
For users, the lesson is simpler: read the contract, not the tweet. Agent-native finance is coming whether the accountability frameworks are ready or not. Until they are, keep your exposure small and your verification layers tight.