Bankr announced on X that it disabled swaps, transfers, and token deployments after confirming an attacker had accessed 14 wallets. The AI crypto trading assistant called the pause a precaution and pledged to reimburse all lost funds.
14 Wallets Breached, Bankr Halts Operations
The team stated it had identified the attacker who compromised the wallets, adding “we’ve temporarily locked things down while we work through the details.” All affected users will be fully compensated. The move followed reports of drained wallets that sparked community concern.
User Advisory: Stop Signing, Create New Wallets Immediately
Bankr advised users not to sign any transactions until further notice. Affected users should stop using compromised wallets, generate new seed phrases on clean devices, and move any remaining tokens or NFTs. If assets cannot be moved, revoke all existing approvals. The team warned that attackers often exploit leftover permissions to drain funds, and recommended scanning computers and phones for malware or suspicious browser extensions.
AI Agent Attack Theory: Social Engineering and Prompt Injection
Yu Xian, founder of SlowMist, said the exploit appeared to be a social engineering attack targeting the trust layer between automated agents. He pointed to a possible interaction between Grok and Bankrbot that allowed unauthorized signing. Yu described it as a mix of social engineering and prompt injection, noting a previous Bankrbot-linked wallet assigned to Grok was drained through a similar method. Bankr’s design as a natural language AI trading companion—enabling swaps, trades, transfers, and token deployments via simple commands in social feeds or a private terminal—makes the case closely watched.
Tech entrepreneur Austen Allred confirmed a Bankr wallet linked to his Kelly Claude AI assistant project was among those compromised. Allred said there was no evidence of unauthorized login to the Bankr account, implying the attacker obtained the keys through another vector.
Recent Crypto Bridge Security Incidents Surge
The Bankr hack comes amid a spate of crypto attacks. Reports show Verus Protocol’s Ethereum bridge lost over $11.5 million after attackers forged a cross-chain transfer message. Echo Protocol paused cross-chain activity after an attacker minted approximately $76.7 million in unauthorized eBTC on Monad. Aethir earlier said it contained a bridge attack while keeping user losses below $90,000. Other DeFi attacks this year involving Drift Protocol and Kelp DAO have further raised concerns over bridge security, wallet approvals, and automated transaction systems.

