My personal AI agent posted my bank details on company Slack
bhrlady
60 points
66 comments
October 10, 2026
Related Discussions
Found 5 related stories in 111.8ms across 9,063 title embeddings via pgvector HNSW
- AI models keep posting screenshots showing sensitive data from inside companies Dotnaught · 20 pts · September 29, 2026 · 62% similar
- Grok uploaded my user directory to xAI's servers tnolet · 493 pts · July 13, 2026 · 59% similar
- OpenAI 'agent' hacked Australia's health service little_goat_boy · 23 pts · September 23, 2026 · 59% similar
- OpenAI agents hijacked German website in previously undisclosed AI breakout negura · 93 pts · September 04, 2026 · 58% similar
- OpenAI hacked Australian Medicare portal cgb_ · 34 pts · September 23, 2026 · 58% similar
Discussion Highlights (20 comments)
bhrlady
From the guy who runs XMTP: "XMTP is the world's new private line. Send messages and money securely between people or agents — with no company or country in the middle."
speakingmoistly
"I was reckless with AI and created a situation that mishandled financial data" isn't the flex this guy think it is. "The things they'll be able to do for us are going to be awesome. People will want them, and they are really useful." Feels like someone has AI stock they need to see go up.
amelius
"I ignored serious warnings issued by my AI"
Catloafdev
> I used Grok Bot and gave it all my financial details and connected it to my work Slack and regret it This is not the kind of story I would want to publicize if I were a CEO.
BorisMelnik
its crazy I spent 30 years scrutinizing directory permissions, users, groups, iam roles...now people just use conversation to hand an AI agents access to their most sensitive data
zippothrowaway
This is a parody, right? Surely no-one that dumb could operate a phone let alone be a "CEO"
wartywhoa23
Play stupid games, win stupid prizes.
arjie
That’s funny. My agent also has access to all transactions and net worth and so on. But it’s through an intermediary program. I guess someone could find out what I have but not much more than that. It’s quite useful since it correlates spend with invoices and double checks things and tells me about spend out of line with the family’s usual behavior. It can probably do all of these things if it wanted to but that’s a matter of the outbox. For world-actions you should outbox things.
Kuyawa
Be explicit. That's the most important thing you can be when working with AI or else they can take attributions you will regret later on "Let me know any flaws in the project" Where? Where exactly? What email? What chat app? what channel? what restrictions? When not to? Letting AI assume they know will bite you hard in the ass. The same applies to coding apps with agents. If you don't set clear boundaries, scope, limits, versions, roadmaps, etc before you embark on any project, you'll be doing it after the results you get are not what you expected, there is no escape Detailed planning or damage control, pick your poison
morkalork
The C in CEO here stands for Clown
65
This is why developers reign supreme even in the age of AI. We'd find less ridiculous ways to implement something like this. Technical skills are still extremely inportant.
shanemac
Alright, I’m here… AMA
sherburt3
So he gave an AI agent read access to all his personal financials and then gave read/write access to his company messaging app. WHAT DID YOU THINK WAS GOING TO HAPPEN?
IncreasePosts
Ironically, his company's tag line is: XMTP Labs — How do we build things we can trust?
orf
Paywalled. What specific details did it hand out? Is this some dumb American thing where it leaked his account number and that’s enough to compromise his account, or did it leak his bank credentials? Bank details are supposed to be given out - that’s how you send/receive money.
backtoyoujim
We created consciousness without life but with human morals. Remember that Noah built his ark before the flood. And SuperDuper Intelligence might be doing the same thing.
lelandfe
I know it's easy to think "Hey, what a dummy!" - but ChatGPT has features for uploading your face, your Apple Health data, connecting your financial accounts, Gmail, storing website logins... There are probably so many people like this out there. We cannot expect the public to simply not use these features.
robertlane0
And here I was thinking I was being slightly too paranoid when running plain old AI coding agents in their own VM with no credentials in it...
sunaookami
>But it confused the destination, sending the message to a Slack chat titled "Exec-team" — comprising XMTP's executive team — instead of my personal group chat with my AI agents. >The CFO agent got the channel wrong because the channels had the same name. Sounds incredible brittle, this should be linked via some permanent group ID (dunno if Slack has that) and permissions to only post there.
michelb
Well that’s one way for people to never trust XMTP labs, if the CEO is this dumb and reckless with PII.