Bankr, an AI-powered crypto trading assistant, paused all transaction capabilities after detecting an attacker accessed at least 14 user wallets, leading to reported losses for some users reaching up to $150,000. The company took swift action to disable swaps, transfers, and token deployments as part of an ongoing investigation into the breach.

Bankr’s platform allows users to execute trades, transfers, and token launches through simple language commands rather than conventional wallet interfaces. It automatically generates a crypto wallet linked to every social media handle interacting with its bot. This automation was exploited previously, when attackers manipulated the system to launch tokens and siphon assets to wallets under their control.

Security analysts suggest the incident likely involved a social engineering attack targeting the trust between automated agents on the platform, specifically interactions between Grok—an AI agent—and Bankrbot. These attacks manipulated transaction signatures without user consent, enabling unauthorized asset transfers. Three attacker addresses connected to this breach reportedly hold around $440,000 in stolen crypto.

Bankr warned users to refrain from signing any transactions until further notice. The company advised anyone with compromised wallets to stop using them immediately, create new wallets with fresh seed phrases generated on secure devices, and transfer any remaining tokens or NFTs to the new addresses. Additionally, users are urged to revoke prior transaction approvals, as attackers often exploit these to drain funds even after the initial breach.

In its security guidance, Bankr highlighted the importance of checking for malware or suspicious browser extensions, especially for those using software wallets where the seed phrase might have been compromised on the user’s device. The company assured it will reimburse all lost funds once the investigation concludes and promised to provide further updates to affected users.

This breach adds to a growing wave of crypto platform exploits observed in recent months, with hackers targeting various decentralized finance protocols and bridges, resulting in hundreds of millions in losses. Bankr’s proactive response underscores the ongoing challenges of securing AI-driven crypto services amid escalating cyber threats.