Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Bankr AI Trading Platform: AI Agent Wallet Security Vulnerability Results in 14 Wallets Drained and $440,000 Stolen

The victims are primarily retail cryptocurrency investors and small-to-medium traders pursuing high returns. Attracted by Bankr's promotional claims of AI trading strategies and automated yields, they delegated their wallet custody to the platform. Victims generally lacked awareness of AI Agent privilege management, ignored security mechanisms such as multi-signatures and timelocks, and placed excessive trust in the platform's claims of "professional AI management" without independently verifying on-chain permissions, allowing social engineering attacks to succeed and funds to be rapidly drained.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal
ScaleSME
ChannelOnline
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The victims are primarily retail cryptocurrency investors and small-to-medium traders pursuing high returns. Attracted by Bankr's promotional claims of AI trading strategies and automated yields, they delegated their wallet custody to the platform. Victims generally lacked awareness of AI Agent privilege management, ignored security mechanisms such as multi-signatures and timelocks, and placed excessive trust in the platform's claims of "professional AI management" without independently verifying on-chain permissions, allowing social engineering attacks to succeed and funds to be rapidly drained.

骗局怎么运作

  • Step 1: The platform attracts users to register by using AI market-making and intelligent trading as gimmicks, promoting concepts like "AI custodial wallets" and "automated strategy execution" via social media and KOLs, promising stable high returns to project a professional and trustworthy image. In reality, the underlying code lacks security audits, and vulnerabilities exist in private key or permission allocation.
  • Step 2: Users are induced to grant wallet permissions to platform contracts or AI Agents. While the platform claims that "AI automatically monitors the market and rebalances positions," the actual permission scope far exceeds what is necessary—including high-risk permissions such as transfers and burns—without setting whitelists or limits. Lulled into a false sense of security by five-star reviews and historical performance reports, users lose control after a one-click authorization.
  • Step 3: Attackers use social engineering methods (such as phishing emails and fake customer support) to steal platform administrator private keys or exploit AI Agent permission vulnerabilities, initiating batch transfers across 14 user wallets. The entire process uses automated scripts to extract assets in a short period without triggering abnormal alerts on the platform monitoring system.
  • Step 4: Funds flow into mixers or decentralized exchanges and are quickly split into small transactions to be laundered. Upon discovering the issue, the platform merely suspends trading without initiating emergency freezes or user compensation, instead issuing an announcement that it "suffered a security incident" and promising compensation without specifying amounts or timelines.
  • Step 5: Victims face difficulties in seeking recourse. Because the project team is anonymous and the contracts are unaudited, losses are hard to recover. In the same month, multiple similar AI platforms were exposed for comparable vulnerabilities, though some project teams took the opportunity to rug pull, deepening industry distrust in AI custody.

红旗信号(看到这些快跑)

  • 🚩 The platform claims "fully automated AI trading," but the code is not open-source and there is no third-party audit report.
  • 🚩 During user authorization, requests are made for "unlimited" or "contract upgrade" permissions, far exceeding standard operations.
  • 🚩 Customer support or community communication occurs solely through unofficial channels like Telegram, with direct messages frequently pushing wallet authorization links.
  • 🚩 Yield promises are abnormally high (e.g., daily returns over 1%), and withdrawals require paying a "deposit" or "unlock fee."
  • 🚩 The project team's identity is anonymous, the whitepaper lacks team information, and the official website lists no company registration location.

真实案例

  • On May 20, 2026, the Bankr AI trading platform suffered a social engineering attack affecting 14 wallets with losses of approximately $440,000. The platform suspended trading and promised compensation, but subsequently failed to disclose progress on compensation (according to Siam Blockchain reports). (Source: [https://siamblockchain.com/2026/05/20/bankr-14-wallets-hacked-440k-transactions-disabled/](https://siamblockchain.com/2026/05/20/bankr-14-wallets-hacked-440k-transactions-disabled/))
  • In September 2026, Term Labs suffered a governance attack involving $8.5 million. The attacker exploited a governance proposal vulnerability to transfer funds via malicious contracts, and a portion of the assets was eventually recovered through negotiations (according to Cointelegraph reports). (Source: [https://cointelegraph.com/news/bankr-disables-transactions-after-14-wallets-hacked](https://cointelegraph.com/news/bankr-disables-transactions-after-14-wallets-hacked))
  • In 2026, the BetterBank project was exploited by hackers due to a reward logic flaw, resulting in massive theft of user rewards. Analytical articles pointed out that the flaw stemmed from a failure to verify reward withdrawal conditions (according to CN-SEC analysis). (Source: [https://cn-sec.com/archives/4645718.html](https://cn-sec.com/archives/4645718.html))

Official Stance

  • On May 20, 2026, Bankr officials announced the "suspension of all trading" on social media and advised users to revoke wallet authorizations, though no specific loss list was provided (Source: CoinTelegraph).
  • In September 2026, following a governance attack on YAM Finance, officials issued a notice reminding users to promptly cancel authorizations to malicious contracts (Source: Gadgets360).
  • In 2026, multiple cryptocurrency exchanges (such as Bybit) issued liquidity mining risk warnings, emphasizing that users must verify project audits and permission settings (Source: Bybit Help Center).

How to Protect Yourself

  • ✅ Before investing, verify whether the project discloses code repositories, audit reports, and real-name team information, and reject anonymous or temporarily assembled teams.
  • ✅ Use an independent hardware wallet to manage assets, actively review permission lists during authorization, and turn off "auto-renewal" and "unlimited" options.
  • ✅ Be wary of any AI trading platform that requires "lock-up unlocks" or "deposit payments" to withdraw funds; normal DeFi protocols do not charge such fees.
  • ✅ Regularly monitor official channels and third-party security monitors (such as ChainCatcher, QuillAudits), and immediately revoke authorizations and transfer assets if abnormalities are detected.