Security expert comments on the risks of giving Grok Bot access to bank accounts 

Users are considering giving Grok Bot access to their bank accounts, with one user suggesting it could “track spending, move money, pay bills, and watch for weird charges.”

Elon Musk encouraged the user to “try it out,” adding that if “Grok Bot messes up, we will make you whole.”

Cybernews information security researcher Rasa Jurgutytė warns that giving an AI agent this level of access could create risks that reimbursement cannot fix.

Her comments:

  • “In this case, where an agent essentially performs bank operations on your behalf, so many things can go wrong. An agent might misunderstand a request at best, or can be manipulated via prompt injections/malicious requests at worst.”
  • By giving Grok Bot access to your data, there’s also a risk of accidental information disclosure.
  • In this context, leaked data could include “your transaction history, balances, payment method, or personal information, which is much worse than a brief summary of your spending habits, or whatever else a person might ask on a prompt,” Jurgutytė told Cybernews.
  • While Musk tells the user not to worry, as he will reimburse potential damages caused by Grok Bot, Musk “cannot undisclose your information,” Jurgutytė concludes.

Feel free to use Rasa’s comments in your coverage. I can also provide additional information if useful.

Here’s the full Cybernews article about this for more context: https://cybernews.com/ai-news/grok-bot-connect-bank-acccount/ 

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading