Bankr got hit. On May 19, 2026, the AI-powered crypto trading platform disclosed that an attacker had drained 14 user wallets on Base, walking away with roughly $170,000. Not a great look for a platform selling the dream of automated, intelligent trading.
Bankr lost $170,000 across 14 wallets in a single breach. Not ideal for a platform selling automated trust.
The stolen funds didn’t just sit there. On-chain activity showed the attacker swapped everything to ETH on Base, then bridged it straight over to Ethereum mainnet. Clean, fast, and gone. Bankr paused transactions after spotting the breach and said the affected wallets were under investigation. They also promised to reimburse the losses, which is something at least.
What made this incident particularly messy was how it happened. Bankr described the drain as a direct transfer call, not the usual transferFrom pattern. That matters because it pointed to transactions signed directly with the wallet’s private key. So this wasn’t a smart contract exploit. Someone, or something, got hold of the keys.
Two likely vectors emerged: a compromised Privy session through a malicious site or browser extension, or a phishing attack that captured a permit or permit2 signature. Either way, users got tricked into signing something they shouldn’t have.
Then the scammers piled on. Because of course they did. A fake airdrop narrative started circulating in the aftermath, pushing additional confusion around BNKR and wallet safety. Classic opportunism. Post-hack chaos is basically a buffet for social engineers. Malicious links, sketchy approval requests, urgent-sounding prompts — all designed to catch people already rattled by the breach news.
No verified on-chain evidence surfaced for any legitimate BNKR airdrop tied to this event. Just noise, designed to steal more.
Bankr told affected users to move funds to fresh wallets on clean devices, scan for malware, check for rogue browser extensions, and cancel any active spending permissions. Recovery guidance that nobody wants to need. Experts consistently recommend proper audit trails and access control protocols as foundational measures that can help platforms detect unauthorized activity before losses escalate.
BNKR plunged after the disclosure hit. That’s the market doing what markets do when trust takes a shot. The breach landed especially hard because Bankr’s whole pitch revolves around AI-powered trading and wallet automation — tools that require users to trust the platform with serious access.
A security event targeting that access doesn’t just hurt wallets. It chips away at the core value proposition. The Bankr incident draws uncomfortable comparisons to the 2016 Bangladesh Bank heist, where hackers spent a full year quietly inside the bank’s systems before executing their attack, a reminder that prolonged undetected access remains one of the most dangerous threats any financial platform can face. North Korea’s tactics follow a similar pattern of patience and precision, having stolen over USD 5 billion in cryptocurrency since 2017 through phishing, supply chain compromises, and private key theft — the very methods implicated in the Bankr breach.
The investigation was still ongoing. The reimbursement commitment was out there. But the damage, both financial and reputational, was already in motion.