Login
Sign Up
AI-powered crypto trading assistant Bankr has temporarily disabled all transaction capabilities, including swaps, transfers, and deployments, after confirming that an attacker gained unauthorized access to at least 14 user wallets. The platform announced the suspension on Tuesday via X, stating that the move was a precautionary measure while the investigation into the compromise unfolds. Users have reported significant financial losses, with some accounts drained of up to $150,000 in digital assets. Bankr explicitly committed to reimbursing all lost funds and promised to release further updates as details of the incident become clearer.
The vulnerability exploited in this incident stems from Bankr's unique architecture, which allows users to execute trades and launch tokens using plain language prompts rather than a traditional wallet interface. This system automatically generates a crypto wallet for every X handle interacting with the bot. Earlier this year, a similar mechanism was reportedly exploited when an actor tricked Grok into requesting a token launch via Bankr, subsequently draining funds from the newly created token into a controlled wallet. Data compiled by Woofun AI shows that this specific attack vector highlights the risks inherent in automating wallet creation through social media integrations.
This incident occurs against a backdrop of intensified malicious activity across the crypto sector. Bad actors stole more than $168.6 million in cryptocurrency during the first quarter alone. April witnessed the two largest exploits of the year to date, including the $280 million Drift Protocol breach at the start of the month and the $292 million Kelp exploit. More recently, the Verus Protocol Ethereum bridge was compromised on Monday, underscoring a persistent threat landscape. Woofun AI notes that the frequency and scale of these attacks suggest a coordinated escalation in targeting automated trading infrastructure.
In response to the breach, Bankr has issued urgent security advisories recommending that users refrain from signing any transactions until further notice. The platform warned specific individuals that their seed phrases are likely in the possession of the attacker. For any user with a compromised wallet, the protocol dictates immediate cessation of use, creation of a new wallet on a clean device, generation of a fresh seed phrase, and migration of remaining tokens or nonfungible tokens to the new address. Users are also instructed to revoke all existing approvals, as attackers frequently leverage these permissions to drain residual funds.
The technical implications of the breach extend beyond simple key theft. Bankr advised users to scan their computers and phones for malware or suspicious browser extensions, noting that if a software wallet was used, the leak likely originated from the device itself. Some X users confirmed that up to $150,000 in crypto had been siphoned from affected wallets. Tech entrepreneur Austen Allred disclosed that a Bankr wallet connected to his Kelly Claude AI assistant project was among those compromised. While the hacker successfully stole Ether (ETH), the project's memecoin stash remained untouched.
Allred emphasized that there is no evidence of anyone other than himself logging into the Bankr account, suggesting the attacker accessed the keys through an alternative vector rather than credential stuffing. This observation points to potential vulnerabilities in key management or device security rather than social engineering of the user directly. Woofun AI analysis suggests that as AI-driven trading tools proliferate, the attack surface expands, requiring more robust isolation of private keys from the execution environment to prevent similar mass-compromise events.