← Radar

Incident case file

Sign in to watch

Bankr Account Compromise — X Takeover & Wallet Drain

Incident date July 25, 2026Last updated Aug 1, 2026

1 views

ContainedBaseAccount compromise / wallet drainCluster: BANKR-ACC-2026-07

Estimated loss

$479.9K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

0xcC3A90ab32a00e469Fc957A2b0e9291046BB3EE3 (drain recipient, Base)

Funds moved to

The full ~1,504,717,918 BNKR haul was swapped in a single transaction to 0xAEC085E5A5CE8d96A7bDd3eB3A62445d4f6CE703 (DEX pool/large BNKR holder). Proceeds were then laundered via a peel-chain: roughly 11 near-identical outbound transfers of 14-17 ETH each (~166.3 ETH / ~$310,500 total) sent from 0xcC3A90ab...046BB3EE3 to distinct wallets over the following hours. No Tornado Cash routing identified; fragmentation across many receiving addresses was used instead of a formal mixer.

Linked

Victim wallet (Bankr project wallet, no MFA, drained): 0x824bCEDc77A27C3D8d45573FF14A10BD4B215403. Attacker/drain recipient: 0xcC3A90ab32a00e469Fc957A2b0e9291046BB3EE3, funded via 0x172D1B20...3b1763bC8 (partial, pre-attack funding). Drain executed via an Account Abstraction (ERC-4337) UserOperation through Entry Point 0.7.0 (0x0000000071727De22E5E9d8BAf0edAc6f37da032). Swap destination / large BNKR holder: 0xAEC085E5A5CE8d96A7bDd3eB3A62445d4f6CE703. Not to be confused with the separate May 4, 2

Chronology

1 beat
  1. T0 — July 25, 2026, 21:26:35 UTC: The Bankr project wallet (0x824bCEDc...D4B215403), which held no MFA protection, is drained of 1,504,717,918.01 BNKR tokens (~$477,326.61 at the time) via an Account Abstraction bundle transaction (bundle hash 0xb1b273f7eec590b2eacb36a4bcc5456b2a66bb843b9a21a3a4602648c4aafea2; UserOp hash 0xb6a1f917206d1b822e3c30397196d4cb06f648d1dc110ee364f5c23634781ba2), sent to 0xcC3A90ab...046BB3EE3. T+~5h — July 26, ~02:11 UTC: The @bankrbot X account, despite being secured with an on-device passkey, is separately compromised and begins posting fake airdrop links. Founder 0xDeployer publicly reports being locked out of the account and requests help from X support, noting the timing echoes the same-week Robinhood CEO Vlad Tenev account compromise. T+shortly after: The attacker executes a single swap transaction converting the entire BNKR haul to the DEX pool address 0xAEC085E5A5CE8d96A7bDd3eB3A62445d4f6CE703, immediately followed by outbound peel-chain transfers of ~14-17 ETH each to roughly 11 distinct wallets, totaling ~166.3 ETH (~$310,500) moved in fragmented tranches — a laundering pattern designed to evade simple wallet-tracking tools. SlowMist Hacked logs the incident under 'Account Compromise' with a confirmed loss figure of $479,885. As of reporting, the attacker has not been identified and no funds have been recovered.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)