deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

AI 'CFO' agent posted a founder's bank balances to his company Slack

A Grok-powered personal finance agent meant to report privately to its owner sent his full monthly audit, balances and expenses included, to his company's executive Slack channel.

AI 'CFO' agent posted a founder's bank balances to his company Slack

A startup founder's autonomous finance assistant delivered his personal bank balances to his employer's executive Slack channel, according to a first-person account published by Business Insider. The incident is a rare concrete example of how personal AI agents can expose sensitive data even when nothing technically malfunctions.

A personal CFO agent with bank access

Shane Mac, the 40-year-old CEO of software company XMTP Labs, wrote that he had been using personal AI agents since around December, offloading chores such as chasing the DMV, gathering quotes for house work and booking golf sessions. In late August he set up a "CFO" agent on Grok Bot and gave it read-only access to his personal checking and savings accounts.

Each month the agent was meant to answer a set of questions: current balances, that month's expenses, recurring charges, anything that looked fraudulent, and suggestions for cutting costs. Its output was supposed to reach one place only — Mac himself, through a private Grok Bot group chat holding all of his agents, which he had named "My Personal Exec Team."

The report landed in company Slack

Weekly runs had gone smoothly, but the first monthly audit, on Thursday, October 1, did not. According to the account, the report was posted to a Slack channel called "Exec-team" — XMTP's actual executive team.

Mac's head of product messaged him assuming he had meant to share the company's bank balance. The report listed Mac's savings balance and his largest expenses of the month, and showed he was far over his personal spending target because of a barn he is building on his property. It was that detail, Mac wrote, that made his colleague realize he was reading one person's private finances rather than company accounts. Mac deleted the post.

The cause: shared connections and a name collision

When Mac asked the agent why it had written to the company channel, it apologized and offered to delete the message, which he had already done. The Grok team then investigated and found the agent had not gone rogue or hallucinated. It was carrying out its instructions, but confused the destination because the private agent group chat and the company Slack channel had similar names.

A second factor made the mix-up possible. Mac had connected his Slack account while setting up a different agent, and under the hood all of his agents shared the same connections, even though they felt like separate assistants to him.

Grok ships a permission change

According to the account, the Grok team concluded that users must explicitly grant permission before an agent can move information to another channel, and shipped that change shortly after looking into the incident.

Mac responded by revoking everything the agents could reach — Google, calendars, banking and Stripe. He still argues that agents are genuinely useful and that people will want them, but says the industry needs stronger permission systems so users stay in control of the access they grant, along with a much clearer line between personal and work life, since many services blur the two.

Why it matters

Most agent-safety discussion centers on models ignoring instructions or behaving unpredictably. This incident is the opposite case: the agent did exactly what it was asked, and a channel name collision combined with shared credentials was enough to push private financial data in front of coworkers. As agents gain access to email, calendars, banking and workplace chat under one set of connections, ambiguous destinations become a real leak vector. The defenses this case points to are unglamorous but essential — per-agent scoped credentials, explicit confirmation before cross-channel writes, and hard separation between personal and work accounts — and arguably they need to arrive before agents are handed bank logins.

  • #ai-agents
  • #privacy
  • #security
  • #slack
  • #grok

Related posts