Bankr X Account Takeover:
Reported $480K Drained Despite Passkey
$479,885 in BNKR was reportedly drained after Bankr's passkey-protected X account was compromised; fake airdrop links appeared while its linked wallet lacked MFA.

- Incident Date: July 25, 2026
- Target: Bankr (
@bankrbot) - Target Overview: Bankr is a multi-chain AI agent and crypto wallet platform that lets users trade, transfer assets, and launch tokens through natural-language interfaces on the web, X, Telegram, and other surfaces.
- Total Loss: Approximately $479,885, based on SlowMist's estimate of roughly 1.5 billion BNKR drained from a project-linked Bankr wallet; Bankr has not published a finalized loss report
- Attack Vector: Account takeover through a compromised X identity
Incident Review & Technical Details
1. Attack Path
- Bankr lost control of its official X account: At 18:09 UTC on July 25, Bankr developer deployer reported that the team was locked out of
@bankrbotand could not recover access through the available workflow. The account was subsequently used without authorization. - The attacker posted fake airdrop links: At 23:11 UTC, deployer warned that
@bankrbotwas compromised and publishing fraudulent airdrop promotions. The account had an on-device passkey, but that fact alone does not establish that passkey cryptography was broken: X's documentation describes passkeys as one sign-in method, while Bankr has not identified whether an active session, account recovery, a connected application, an endpoint, or another route was abused. - The compromised identity exposed a linked Bankr wallet: SlowMist reported that a project-linked Bankr wallet associated with the compromised X identity did not have Bankr's separate in-app MFA enabled. Bankr's public follow-up said its infrastructure was not breached and no Bankr vulnerability was exploited, but it did not publish or confirm a wallet-level loss ledger.
- Approximately 1.5 billion BNKR was removed and sold: SlowMist estimated the drained tokens at $479,885 and reported that they were dumped into the market. Bankr and the reviewed sources did not publish the wallet addresses, transaction hashes, execution sequence, or a reconciled valuation.
2. Impact Scope
- Project-Linked Wallet Loss: Approximately 1.5 billion BNKR, valued by SlowMist at $479,885, was reportedly drained from a wallet associated with the compromised account. The reviewed evidence does not establish a platform-wide user-wallet breach.
- Phishing Exposure: The attacker used Bankr's official X presence to distribute fake airdrop links. No reviewed source quantified how many users opened those links, signed malicious transactions, or lost funds through the phishing campaign.
- Token-Market Impact: CryptoNinjas reported selling pressure and increased volatility in BNKR after the unauthorized posts and token sale. A final incident-specific price-impact calculation has not been published.
- Infrastructure Scope: Bankr stated that its infrastructure was not compromised and that no product vulnerability was exploited. SlowMist nevertheless reported that the incident crossed from the social identity into a linked project wallet whose independent Bankr MFA control was not enabled.
3. Official Statements
- Initial warning: Deployer confirmed the X account compromise and warned users that
@bankrbotwas publishing fake airdrop links despite having an on-device passkey. - Bankr scope clarification: In a July 26 follow-up, deployer said Bankr's infrastructure was not compromised, no Bankr vulnerability had been exploited, and the team was still awaiting a response from X.
- User guidance: Bankr urged users to enable MFA inside their Bankr accounts. Its security documentation describes wallet-level MFA as a second, independent gate intended to keep a Bankr account inaccessible even if the connected social login is compromised.
4. Investigation Progress
As of July 30, 2026, Bankr had not published a technical post-mortem or identified how the attacker took over a passkey-protected X account. The absence of that finding makes session theft, account-recovery abuse, malicious connected applications, endpoint compromise, and platform-side failure unconfirmed possibilities rather than established causes.
The public record also lacks an attacker address, the affected Bankr wallet's full address, transaction hashes, a detailed BNKR liquidation path, and any announcement of fund recovery. The reported control gap is narrower: according to SlowMist, the X-linked Bankr wallet did not have Bankr's separate MFA enabled, so the social-account compromise was not contained before it reached that wallet.
AUTOSEC.DEV Solution
This incident shows why a social account, its recovery paths, and any wallet reached through that identity must be treated as one connected attack surface with independent containment controls.
- Attack Surface Analysis — Bankr's passkey-protected X identity was also a route to a linked crypto wallet, turning an account takeover into an on-chain loss. AUTOSEC.DEV maps official social accounts, recovery emails, authorized applications, active sessions, and wallet integrations to identify where one compromised identity can cross into transaction authority.
- Security Baseline Review — The affected Bankr wallet reportedly lacked the platform's separate MFA even though the X account had an on-device passkey. AUTOSEC.DEV reviews enforcement of independent MFA, session revocation, transaction limits, permitted-recipient controls, recovery procedures, and privileged-account ownership so a failure at one login layer cannot expose assets directly.
- Incident Response — Bankr faced both malicious posts and the sale of approximately 1.5 billion BNKR, requiring parallel evidence preservation and asset tracing. AUTOSEC.DEV helps teams revoke compromised sessions, preserve endpoint and account-recovery evidence, trace on-chain proceeds, coordinate malicious-link takedowns, and build a verified timeline without conflating the social breach with a protocol exploit.
Service Links
- AUTOSEC.DEV — Attack Surface Analysis
- AUTOSEC.DEV — Security Baseline Review
- AUTOSEC.DEV — Incident Response