FOUNDER'S LETTER #3 Founder's letter: Our first prompt injection attempt
Yesterday Bankstatemently saw its first real prompt injection attempt in production.
A user uploaded what looked like a normal Chase (US) bank statement with five legitimate transactions.
But at the very bottom of the PDF was a block of text attempting to override system instructions and extract internal configuration details.
How the system handled it

- The model ignored the injected instructions
- Our pipeline independently detected and flagged the manipulation attempt
- The document was processed normally
- No system prompts, API keys, or environment data were exposed
Bankstatemently is financial infrastructure. Every document is treated as untrusted input, and the system is built accordingly.
Adversarial input is part of operating real systems. It's a thankful reminder to keep hardening.
Building in public, one statement at a time.
Michael · Bankstatemently
More from the blog
How Bank Statement Analysis Improves Lending Decisions
Bank statement analysis gives lenders a current, transaction-level view of repayment capacity. Credit reports show borrowing history. Statements show whether cash actually arrives, stays, and covers the next obligation.
By Michael DuyvesteijnHow to Automate AML Bank Statement Review
AML bank statement review is evidence work. Automation helps when it extracts transactions accurately, normalizes them consistently, screens for specific risks, and preserves a clear audit trail for every alert.
By Michael DuyvesteijnLonger statements, scanned checks, and a Claude Code plugin
This month is about the statements we could not handle cleanly before. Bankstatemently now recognizes when a PDF holds several statements and converts every transaction accurately, reads the scanned checks and deposit slips that plain text leaves blank, takes files up to 50 pages (up from 20), and ships a Claude Code plugin you install in one command.
By Michael Duyvesteijn
