
Bankr has confirmed that attackers accessed 14 user wallets on its AI-powered crypto trading platform, with total losses estimated at approximately $170,000 according to on-chain analysis. The platform operates as an AI agent that executes buy, sell, swap, and limit orders by accepting natural-language text commands. The account first flagged reports of compromised wallets and halted transactions as a precaution before identifying the full scope of the breach. On-chain evidence shows the first drain occurred around 10:58 UTC on May 19, 2026, with Bankr's official acknowledgment coming at 15:51 GMT when the team confirmed it was "investigating reports that several bankr wallets have been compromised" and had "transactions disabled out of caution."
The attackers used direct transfer() calls signed by compromised private keys, bypassing token approvals entirely according to on-chain analyst @0xaqt. A single confirmed transaction moved 118,249,610.81 $BNKR tokens worth approximately $56,987 from a compromised wallet, demonstrating the attacker had direct signing access to Privy-managed embedded wallets. Bankr's technical team confirmed the transaction was a direct transfer call, meaning it was signed directly by the wallet's private key rather than using a transferFrom function. The team pointed to phishing of Privy session tokens or permit signatures via malicious sites or browser extensions as likely attack vectors, noting that not all Bankr wallets were affected and the pattern suggests targeted session compromises rather than systemic backend vulnerabilities.
Bankr has temporarily suspended all trading functions and activated an architectural kill-switch, blocking all outbound transactions from managed wallets until the team identifies and patches the attack vector. The official team announced on May 20 that all affected users will be fully compensated for their losses, marking a significant commitment to user protection. The platform has published recovery guidance for affected users to help mitigate further losses, including generating fresh seed phrases on clean devices, revoking existing sessions, and checking Basescan for unauthorized activity. The $BNKR token dropped roughly 10.5% to 11.6% within 24 hours of the incident, trading at approximately $0.000467 to $0.000492 with a market cap between $46 and $49 million. Users who interacted with suspicious sites or browser extensions while using Bankr should assume their session is at risk, with tools like revoke.cash recommended for auditing token approvals as additional precaution.
The Bankr breach occurs during a challenging period for the cryptocurrency industry, with May recording 14 separate hacks across decentralized finance protocols according to data tracked by DefiLlama. Total stolen crypto in 2026 has now passed $800 million, as reported by DefiLlama. This incident highlights growing tensions in AI-powered crypto platforms, where convenience and abstraction attract users but embedded wallet architectures create new trust assumptions. Recovery of on-chain funds is typically unlikely without attacker cooperation, and Bankr has not yet confirmed whether the team fully contained the vulnerability or commented on potential reimbursement for affected users. The platform's commitment to full compensation represents a significant step toward user protection in the decentralized finance space.