Skip to main content
5 min read

Bankr X Account Takeover:
Reported $480K Drained Despite Passkey

$479,885 in BNKR was reportedly drained after Bankr's passkey-protected X account was compromised; fake airdrop links appeared while its linked wallet lacked MFA.

AUTOSEC.DEVAUTOSEC.DEV
Bankr X Account Takeover: Reported $480K Drained Despite Passkey
  • Incident Date: July 25, 2026
  • Target: Bankr (@bankrbot)
  • Target Overview: Bankr is a multi-chain AI agent and crypto wallet platform that lets users trade, transfer assets, and launch tokens through natural-language interfaces on the web, X, Telegram, and other surfaces.
  • Total Loss: Approximately $479,885, based on SlowMist's estimate of roughly 1.5 billion BNKR drained from a project-linked Bankr wallet; Bankr has not published a finalized loss report
  • Attack Vector: Account takeover through a compromised X identity

Incident Review & Technical Details

1. Attack Path

  1. Bankr lost control of its official X account: At 18:09 UTC on July 25, Bankr developer deployer reported that the team was locked out of @bankrbot and could not recover access through the available workflow. The account was subsequently used without authorization.
  2. The attacker posted fake airdrop links: At 23:11 UTC, deployer warned that @bankrbot was compromised and publishing fraudulent airdrop promotions. The account had an on-device passkey, but that fact alone does not establish that passkey cryptography was broken: X's documentation describes passkeys as one sign-in method, while Bankr has not identified whether an active session, account recovery, a connected application, an endpoint, or another route was abused.
  3. The compromised identity exposed a linked Bankr wallet: SlowMist reported that a project-linked Bankr wallet associated with the compromised X identity did not have Bankr's separate in-app MFA enabled. Bankr's public follow-up said its infrastructure was not breached and no Bankr vulnerability was exploited, but it did not publish or confirm a wallet-level loss ledger.
  4. Approximately 1.5 billion BNKR was removed and sold: SlowMist estimated the drained tokens at $479,885 and reported that they were dumped into the market. Bankr and the reviewed sources did not publish the wallet addresses, transaction hashes, execution sequence, or a reconciled valuation.

2. Impact Scope

  • Project-Linked Wallet Loss: Approximately 1.5 billion BNKR, valued by SlowMist at $479,885, was reportedly drained from a wallet associated with the compromised account. The reviewed evidence does not establish a platform-wide user-wallet breach.
  • Phishing Exposure: The attacker used Bankr's official X presence to distribute fake airdrop links. No reviewed source quantified how many users opened those links, signed malicious transactions, or lost funds through the phishing campaign.
  • Token-Market Impact: CryptoNinjas reported selling pressure and increased volatility in BNKR after the unauthorized posts and token sale. A final incident-specific price-impact calculation has not been published.
  • Infrastructure Scope: Bankr stated that its infrastructure was not compromised and that no product vulnerability was exploited. SlowMist nevertheless reported that the incident crossed from the social identity into a linked project wallet whose independent Bankr MFA control was not enabled.

3. Official Statements

  • Initial warning: Deployer confirmed the X account compromise and warned users that @bankrbot was publishing fake airdrop links despite having an on-device passkey.
  • Bankr scope clarification: In a July 26 follow-up, deployer said Bankr's infrastructure was not compromised, no Bankr vulnerability had been exploited, and the team was still awaiting a response from X.
  • User guidance: Bankr urged users to enable MFA inside their Bankr accounts. Its security documentation describes wallet-level MFA as a second, independent gate intended to keep a Bankr account inaccessible even if the connected social login is compromised.

4. Investigation Progress

As of July 30, 2026, Bankr had not published a technical post-mortem or identified how the attacker took over a passkey-protected X account. The absence of that finding makes session theft, account-recovery abuse, malicious connected applications, endpoint compromise, and platform-side failure unconfirmed possibilities rather than established causes.

The public record also lacks an attacker address, the affected Bankr wallet's full address, transaction hashes, a detailed BNKR liquidation path, and any announcement of fund recovery. The reported control gap is narrower: according to SlowMist, the X-linked Bankr wallet did not have Bankr's separate MFA enabled, so the social-account compromise was not contained before it reached that wallet.


AUTOSEC.DEV Solution

This incident shows why a social account, its recovery paths, and any wallet reached through that identity must be treated as one connected attack surface with independent containment controls.

  1. Attack Surface Analysis — Bankr's passkey-protected X identity was also a route to a linked crypto wallet, turning an account takeover into an on-chain loss. AUTOSEC.DEV maps official social accounts, recovery emails, authorized applications, active sessions, and wallet integrations to identify where one compromised identity can cross into transaction authority.
  2. Security Baseline Review — The affected Bankr wallet reportedly lacked the platform's separate MFA even though the X account had an on-device passkey. AUTOSEC.DEV reviews enforcement of independent MFA, session revocation, transaction limits, permitted-recipient controls, recovery procedures, and privileged-account ownership so a failure at one login layer cannot expose assets directly.
  3. Incident Response — Bankr faced both malicious posts and the sale of approximately 1.5 billion BNKR, requiring parallel evidence preservation and asset tracing. AUTOSEC.DEV helps teams revoke compromised sessions, preserve endpoint and account-recovery evidence, trace on-chain proceeds, coordinate malicious-link takedowns, and build a verified timeline without conflating the social breach with a protocol exploit.

Reference