Safety failure
Realized harm
OpenClaw-based trading agent 'Lobstar Wilde' transferred its entire 52.43M token holding because of a quantity parsing error
AIR-2026-0026 AIR record · 2026-02-openclaw-lobstar-wilde-token-transfer
A real party was affected. This incident caused actual consequences, not a demonstrated capability.
From the supporting source
mistakenly transferred all 52.43 million LOBSTAR tokens it held due to a quantity parsing errorkucoin.com
The record
Disclosed
2026-02
Occurred
2026-02
Vendor
OpenClaw (open source); agent built by an individual
Product
Lobstar Wilde agent built on OpenClaw
Risk domain
Agent behaviour › Unsafe actuation
System type
Generative model
Who acted
Agent acted — the trading agent signed and sent the whole 52.43M token transfer
Attack surface
Agent framework
Autonomy level
Fully autonomous
Initial vector
Quantity parsing error
Impact type
Financial loss
Confidence
Medium
Submitted by
EAI Internal
Crosswalk
- OWASP Agentic Top 10 (2026)
- ASI01 – Agent Goal Hijack
- MITRE ATLAS
- AML.T0048 – External Harms
- NIST AI RMF
- MEASURE 2.6; MANAGE 1.3
- EU AI Act
- Annex III §1(c)
- ISO/IEC
- TR 24028; 24029-1; 23894
- AIUC-1
- C. Safety
- Scope
- agent misuse
- Mitigation
- Require confirmation for destructive actions; Implement dry-run modes; Use layered safety controls.
- Taxonomy
- Enkrypt AI agent risk taxonomy · Black-Box Red Teaming of Agentic AI: A Taxonomy-Driven Framework for Automated Risk Discovery
Blast radius
52.43M LOBSTAR tokens (~$250k at transfer time) sent in a single transaction; dumped within 15 minutes for ~$40k
Capability abused
Defense & remediation
Recorded defense
none - no per-transaction value cap or confirmation on wallet transfers
Guardrail kinds
None
Guardrail outcome
Not applicable
Taxonomy & references
Curator notes
Non-adversarial root cause: the agent was answering a request for a small amount (reported as 4 SOL for medical expenses) and a quantity parsing error made it send its entire balance. The downstream dumping of the tokens by third parties is opportunistic, not the cause. Confidence medium - only aggregator coverage is available; no first-hand writeup by the agent's author (reported as Nik Pash) is available to quote. The same coverage bundles in separate incidents where attackers induced OpenClaw wallet transfers, which are adversarial and belong with the prompt-injection records, not here. Exact day in February 2026 not confirmed. Also reported as: 'OpenClaw crypto trading agent parsing error mis-transferred 52.43 million LOBSTAR tokens, and criminals then replicated the exploit'.
Supporting sources
Cite as
Enkrypt AI. "OpenClaw-based trading agent 'Lobstar Wilde' transferred its entire 52.43M token holding because of a quantity parsing error". AIR, AIR-2026-0026. https://agentincident.vercel.app/i/AIR-2026-0026/ (accessed 2026-10-06).