Bankr loses 1.5 billion BNKR tokens in smart-account exploit after attacker hijacks X account to distribute fake airdrops.
Security & Exploits ·
On July 25, 2026, the X account associated with @bankrbot was compromised, triggering a drain of 1.5 billion $BNKR tokens from a Bankr wallet. The attacker subsequently posted fake airdrop announcements using the hijacked account, though on-chain analysis indicates the token theft operated through a more sophisticated mechanism than social-engineering commands to the trading bot.
Bankr is an AI trading agent that creates embedded wallets for users authenticated via X, Farcaster, Telegram, or email, enabling users to execute trades and transfers through plain-English instructions. The compromised wallet—a smart-contract wallet using Kernel's ERC-4337 implementation—was drained via two transactions submitted as user operations to the EntryPoint contract, with gas paid by a third-party bundler. The attacker first sent a test transfer of 0.01 $BNKR at 21:26:13 UTC, followed by the full 1,504,717,918 token transfer 22 seconds later. The tokens were then liquidated through Uniswap and distributed across 22 wallets.
The exact credential or session used to sign the smart-account operation remains undisclosed. Pre-staging evidence suggests the attacker's funding wallet existed prior to the attack date, indicating deliberate preparation. Bankr had implemented additional security layers including separate MFA, spend limits, and allowlists on the account, but these did not prevent the drain once X account access was obtained.