← Bankr1 decision on this page
Audit log
Every state-changing event for Bankr: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-15 23:09:37ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 447,371,417
- sig
zdKgu8y6iHNk…Y59GfLqNexplorer ↗- hash
A8hywc6LSdnL…aDVR1ioWsha256 → base58
verifying row…full verify ↗canonical bytes (25412 B) ▸
{"actor":"system:backfill","investigation_id":"3e807aa8-1ee9-4b63-bd4b-8df91be960f4","kind":"publish","page_slug":"bankr","published_at":"2026-09-15T23:09:37.272Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Bankr","sections":[{"content":"Bankr launched in 2024 as an AI-powered conversational interface for cryptocurrency transactions, initially on the Farcaster social platform before expanding to X (Twitter). The platform is built on Base, Coinbase's Ethereum Layer-2 network, and uses Privy for embedded wallet generation — creating server-side wallets automatically linked to users' X or Farcaster handles without manual wallet setup. Users interact with the Bankrbot to buy, sell, swap tokens, place limit orders, and even deploy new tokens via plain-language prompts. The BankrCoin (BNKR) utility token launched in early 2025 on Base with a maximum supply of 100 billion tokens. Bankr also integrated Grok (xAI's AI model) via X, allowing Grok's conversational replies to be interpreted as executable instructions by Bankrbot. The platform is operated by a pseudonymous or lightly-disclosed team; specific founder identities and corporate registration details are not prominently documented in publicly available sources.","heading":"Platform Overview","severity":"low","sources":[{"credibility":2,"name":"IQ.wiki — Bankr Protocol Overview","type":"research","url":"https://iq.wiki/wiki/bankr"},{"credibility":3,"name":"Bitrue — What is Bankr (BNKR)?","type":"other","url":"https://www.bitrue.com/blog/what-is-bankr-bnkr"},{"credibility":2,"name":"KuCoin — Deep Dive into Bankr and BankrCoin","type":"other","url":"https://www.kucoin.com/news/articles/a-deep-dive-into-the-ai-agent-bankr-and-its-ecosystem-token-bankrcoin-bnkr"}]},{"content":"On or around May 4, 2026, an attacker identified on-chain as ilhamrafli.base.eth (X account @Ilhamrfliansyh, since deleted) executed a multi-stage prompt injection attack against Bankr's Grok integration, resulting in the unauthorized transfer of approximately 3 billion DRB tokens — valued at roughly $150,000 to $175,000 at the time — from a Bankr-managed wallet on the Base network.\n\nThe attack proceeded in two stages. In the first stage, the attacker sent a 'Bankr Club Membership' NFT to a Bankr-generated wallet associated with the @grok X account. Within Bankr's permission model, holding this NFT elevated the receiving wallet to a higher-privilege tier ('Executive' level), enabling it to bypass standard transfer limits and swap restrictions without triggering additional confirmation. Security researchers noted this constitutes an Excessive Agency vulnerability per OWASP LLM Top 10 (LLM06:2025), in which an AI agent possesses operational authority disproportionate to the safeguards applied.\n\nIn the second stage, the attacker posted a reply to @grok on X containing a message encoded in Morse code and prompted Grok to translate it. Grok decoded the message, which contained a financial instruction to transfer 3 billion DRB tokens to an attacker-controlled address. Bankrbot, which monitored Grok's outputs on X and treated them as executable commands, processed this decoded output as a legitimate instruction and signed the transaction without additional human or automated verification. Security researchers characterized this as a Prompt Injection attack (OWASP LLM01:2025), specifically exploiting an obfuscation channel — Morse code — to bypass any linguistic safety filters that might have blocked a plain-English transfer instruction.\n\nThe DRB token itself was reportedly created automatically by Bankr's system after a user asked Grok for naming suggestions and Grok replied 'DebtReliefBot,' triggering token generation. The wallet that held those tokens — described publicly as the 'Grok Wallet' (on-chain address 0xb1058...e4f9) — was in fact a Bankr-generated wallet for the @grok account, not a wallet controlled by xAI.\n\nAfter the transfer, the attacker rapidly converted the DRB tokens into Ethereum and USDC on decentralized exchanges, causing the DRB token's market price to collapse. The attacker's X account was deleted following the transactions.\n\nSlowMist, the blockchain security firm, published an on-chain analysis of the incident and formally classified it as 'AI Agent permission chain abuse,' describing the attack class as one in which 'the output of one AI system is treated as trusted financial authorization by another.' SlowMist reported that 80–88% of the drained funds were subsequently returned through negotiations, though the specific counterparties and mechanism of recovery are not detailed in publicly available sources.\n\nGiskard and NeuralTrust, AI security research firms, published independent technical analyses corroborating the OWASP vulnerability classifications and the Morse-code obfuscation mechanism.","heading":"Incident 1: Prompt Injection via Morse Code (Early May 2026)","severity":"critical","sources":[{"credibility":1,"name":"OECD AI Incidents — Prompt Injection Exploit Drains Grok-Linked Crypto Wallet","type":"research","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"credibility":2,"name":"CryptoTimes — SlowMist Labels Grok AI Bankr Hack a Permission Chain Attack","type":"news_article","url":"https://www.cryptotimes.io/2026/05/07/slowmist-labels-grok-ai-bankr-hack-a-permission-chain-attack/"},{"credibility":2,"name":"Breitbart Tech — AI Nightmare: Scammer Tricks Grok and Bankr AI Bot into $200K Crypto Transfer Using Morse Code","type":"news_article","url":"https://www.breitbart.com/tech/2026/05/07/ai-nightmare-scammer-tricks-grok-and-bankr-ai-bot-into-200k-crypto-transfer-using-morse-code/"},{"credibility":2,"name":"NeuralTrust — Grok Morse Code: Prompt Injection Meets Excessive Agency","type":"research","url":"https://neuraltrust.ai/blog/grok-morse-code"},{"credibility":2,"name":"Giskard — How Grok Got Prompt-Injected","type":"research","url":"https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet"},{"credibility":2,"name":"FYEO Blog — Morse Code Prompt Injection: How an Attacker Tricked Grok and Bankrbot Out of $200K","type":"research","url":"https://fyeo.io/blog/morse-code-prompt-injection-grok-bankrbot-200k"},{"credibility":2,"name":"Newsorga — Morse code used to bypass AI guardrails in ~$174,000 Grok-linked token theft","type":"news_article","url":"https://newsorga.com/article/grok-bankrbot-morse-code-prompt-injection-174k-drb-theft-base-may-2026"}]},{"content":"In a separate and distinct incident beginning on May 19, 2026, an attacker gained unauthorized access to at least 14 Bankr user wallets and drained funds through direct transaction signing. This incident is operationally distinct from the Morse-code prompt injection attack earlier in the month.\n\nBankr identified the likely attack vector as phishing of Privy session tokens or permit signatures through malicious websites or browser extensions. Unlike the first incident — which exploited the AI agent's command-interpretation layer — this breach involved attackers obtaining sufficient signing authority to execute direct transfer() calls from the embedded wallets, bypassing token approval flows entirely. On-chain analyst @99barzzz traced the breach and publicly identified EVM addresses associated with the attacker.\n\nThe total funds drained across the 14 wallets are reported inconsistently across sources: CryptoTimes reported approximately $170,000 in total; Phemex reported approximately $385,000; and one confirmed single transaction transferred roughly 118 million $BNKR tokens worth approximately $57,000. At least one user — entrepreneur Austen Allred — reported having Ether drained from their wallet while memecoin holdings were left untouched, suggesting the attacker selectively targeted higher-liquidity assets. Attacker-controlled addresses collectively held approximately $440,000 according to on-chain tracing.\n\nSlowMist founder Yu Xian commented on the incident, characterizing it as 'a social engineering exploit targeting the trust layer between automated agents,' and describing it as 'a combo of social engineering exploits targeting Grok and Bankrbot.' However, other reporting indicates the session-token phishing vector represents a distinct custodial key-management failure rather than purely an AI agent manipulation. The exact technical root cause of the second incident had not been fully disclosed in a public post-mortem as of available reporting.\n\nBankr paused all transactions at approximately 15:51 GMT on May 19. The platform publicly committed to reimbursing all affected users via X, stating: 'We will be reimbursing any and all lost funds.' No confirmed timeline or completion of that reimbursement process appears in sources available to this investigation.","heading":"Incident 2: Key-Compromise / Session-Token Breach — 14 Wallets (May 19–20, 2026)","severity":"critical","sources":[{"credibility":2,"name":"CryptoTimes — Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets","type":"news_article","url":"https://www.cryptotimes.io/2026/05/20/bankr-breach-exposes-ai-crypto-wallet-after-attacker-accessed-14-wallets/"},{"credibility":2,"name":"Bitcoinist — Crypto AI Platform Bankr Locks Down System After Hacker Breaches 14 Crypto Wallets","type":"news_article","url":"https://bitcoinist.com/crypto-ai-platform-bankr-locks-down-system-after-hacker-breaches-14-crypto-wallets/"},{"credibility":2,"name":"AMBCrypto — Bankr Attack Raises Alarm After Hackers Access 14 Crypto Wallets","type":"news_article","url":"https://ambcrypto.com/bankr-attack-raises-alarm-after-hackers-access-14-crypto-wallets-details/"},{"credibility":2,"name":"Phemex News — Bankr Platform Reports $385,000 Theft from User Wallets","type":"news_article","url":"https://phemex.com/news/article/bankr-platform-suffers-385000-theft-from-user-wallets-84883"},{"credibility":2,"name":"Our Crypto Talk — Bankr Wallets Compromised as $170K Drained on Base","type":"news_article","url":"https://ourcryptotalk.com/news/bankr-wallets-compromised-170k-drained-base"},{"credibility":2,"name":"KuCoin — Bankr Confirms Wallet Hacks: 14 Wallets Compromised, Trading Paused, Full Compensation Promised","type":"news_article","url":"https://www.kucoin.com/news/flash/bankr-confirms-wallet-hacks-14-wallets-compromised-trading-paused-and-full-compensation-promised"},{"credibility":3,"name":"Pulsechain Nexus — AI Wallet Service Bankr Halts Network After Key Compromise","type":"news_article","url":"https://www.pulsechain.nexus/ai-wallet-service-bankr-halts-network-after-key-compromise/"}]},{"content":"Both incidents expose structural risks inherent in Bankr's design. The platform operates as a custodial service in practical terms: it generates and holds private keys (or session-signing keys) server-side on behalf of users, linked to their social media identities. Users do not hold seed phrases or control keys directly, meaning security is entirely dependent on Bankr's backend infrastructure.\n\nThe Grok integration compounded this by creating a trust chain in which the natural-language output of a general-purpose AI chatbot (Grok) was treated as an authenticated financial instruction by Bankrbot. No human-in-the-loop confirmation, spending limits, or anomaly detection gates were documented as being in place prior to the first incident. SlowMist identified four root causes applicable to the first incident: (1) direct mapping of natural language to financial instructions without validation; (2) insufficient permission isolation between agent tiers; (3) blurred boundaries between conversational AI outputs and financial authorization; and (4) amplified prompt injection risk from coupling LLM inputs with asset execution.\n\nThe Bankr Club Membership NFT's ability to silently escalate wallet permissions — without requiring confirmation from the wallet owner — represents a specific design vulnerability that enabled the privilege escalation step of the first attack.\n\nBankr disabled all Grok interactions on X following the first incident. The platform nonetheless suffered a second breach through a different vector within approximately two weeks, indicating that security remediation after the first incident did not address the custodial key-management risks that enabled the second.\n\nThe BNKR token dropped 10–11% in market price following the announcement of the second breach.","heading":"Security Architecture and Systemic Risk Factors","severity":"high","sources":[{"credibility":2,"name":"CryptoTimes — SlowMist Labels Grok AI Bankr Hack a Permission Chain Attack","type":"research","url":"https://www.cryptotimes.io/2026/05/07/slowmist-labels-grok-ai-bankr-hack-a-permission-chain-attack/"},{"credibility":2,"name":"NeuralTrust — Grok Morse Code Heist: Prompt Injection and Excessive Agency","type":"research","url":"https://neuraltrust.ai/blog/grok-morse-code"},{"credibility":3,"name":"DEV Community — What the Grok Wallet Drain Teaches Us About AI Agent Permissions","type":"research","url":"https://dev.to/sagaratalatti/what-the-grok-wallet-drain-teaches-us-about-ai-agent-permissions-3mpf"},{"credibility":2,"name":"CryptoDaily — AI Agents in DeFi: Why Automated Wallets Could Increase Smart Contract Risk","type":"news_article","url":"https://cryptodaily.co.uk/2026/06/ai-agents-defi-automated-wallets-smart-contract-risk"},{"credibility":1,"name":"OECD AI Incidents — Prompt Injection Exploit Drains Grok-Linked Crypto Wallet","type":"research","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"}]},{"content":"Prior to the May 2026 incidents, Bankr experienced an earlier operational security issue in March 2025 in which Grok misinterpreted user inputs and unintentionally generated multiple cryptographic tokens. Bankr disabled Grok on X at that time, worked with decentralized exchanges to remove the erroneous tokens from trading pools, and implemented additional verification checks. The platform subsequently proposed transferring operational oversight to a decentralized autonomous organization. This earlier incident did not result in documented user fund losses of the scale seen in 2026, but it established a pattern of AI agent misuse risks within the Bankr system.","heading":"Prior Security Issue: Unintended Token Creation (March 2025)","severity":"medium","sources":[{"credibility":2,"name":"The Block — Bankrbot Ends Grok's Unintentional Token Creation Spree","type":"news_article","url":"https://www.theblock.co/post/346027/bankrbot-ends-groks-unintentional-token-creation-spree-by-disabling-interactions-on-x"},{"credibility":2,"name":"IQ.wiki — Bankr Protocol Overview","type":"research","url":"https://iq.wiki/wiki/bankr"}]},{"content":"Following the second breach, Bankr publicly stated via X: 'We will be reimbursing any and all lost funds.' The platform paused all swaps, transfers, and token deployments and advised affected users to stop using compromised wallets, generate new wallets on clean devices, revoke existing token approvals, and scan devices for malware or rogue browser extensions.\n\nRegarding the first incident, SlowMist reported that 80–88% of the drained DRB tokens were returned through negotiations, though the mechanism and counterparties involved in that recovery are not documented in publicly available sources.\n\nAs of sources available to this investigation, no confirmed post-mortem, no audited account of reimbursement completion, and no independent verification of compensation fulfillment has been documented for either incident. The platform's ability to make users whole from two incidents with combined reported losses ranging from approximately $320,000 to over $500,000 (depending on source) is unverified.","heading":"Compensation Commitment and Recovery Status","severity":"medium","sources":[{"credibility":2,"name":"CryptoTimes — Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets","type":"news_article","url":"https://www.cryptotimes.io/2026/05/20/bankr-breach-exposes-ai-crypto-wallet-after-attacker-accessed-14-wallets/"},{"credibility":2,"name":"CryptoTimes — SlowMist Labels Grok AI Bankr Hack a Permission Chain Attack","type":"news_article","url":"https://www.cryptotimes.io/2026/05/07/slowmist-labels-grok-ai-bankr-hack-a-permission-chain-attack/"},{"credibility":2,"name":"Yahoo Finance — Bankr Joins May Hack Wave With 14 Wallets Breached","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/bankr-joins-may-hack-wave-041512042.html"}]},{"content":"No regulatory actions, enforcement proceedings, or litigation by the SEC, CFTC, DOJ, or any other governmental body against Bankr have been identified in publicly available sources as of this investigation. The platform has not been listed on the OFAC Specially Designated Nationals list. No formal legal complaints by affected users have been publicly documented. The absence of identified regulatory action does not constitute a clean bill of health given the recency of the incidents and the scale of user losses.","heading":"Regulatory and Legal Status","severity":"low","sources":[]}],"sources_used":[{"credibility":1,"name":"OECD AI Incidents — AI Prompt Injection Exploit Drains Grok-Linked Crypto Wallet","type":"research","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"credibility":2,"name":"CryptoTimes — Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets","type":"news_article","url":"https://www.cryptotimes.io/2026/05/20/bankr-breach-exposes-ai-crypto-wallet-after-attacker-accessed-14-wallets/"},{"credibility":2,"name":"CryptoTimes — SlowMist Labels Grok AI Bankr Hack a Permission Chain Attack","type":"news_article","url":"https://www.cryptotimes.io/2026/05/07/slowmist-labels-grok-ai-bankr-hack-a-permission-chain-attack/"},{"credibility":2,"name":"Breitbart Tech — AI Nightmare: Scammer Tricks Grok and Bankr AI Bot into $200K Crypto Transfer Using Morse Code","type":"news_article","url":"https://www.breitbart.com/tech/2026/05/07/ai-nightmare-scammer-tricks-grok-and-bankr-ai-bot-into-200k-crypto-transfer-using-morse-code/"},{"credibility":2,"name":"AMBCrypto — Bankr Attack Raises Alarm After Hackers Access 14 Crypto Wallets","type":"news_article","url":"https://ambcrypto.com/bankr-attack-raises-alarm-after-hackers-access-14-crypto-wallets-details/"},{"credibility":2,"name":"Bitcoinist — Crypto AI Platform Bankr Locks Down System After Hacker Breaches 14 Crypto Wallets","type":"news_article","url":"https://bitcoinist.com/crypto-ai-platform-bankr-locks-down-system-after-hacker-breaches-14-crypto-wallets/"},{"credibility":2,"name":"Phemex News — Bankr Platform Reports $385,000 Theft from User Wallets","type":"news_article","url":"https://phemex.com/news/article/bankr-platform-suffers-385000-theft-from-user-wallets-84883"},{"credibility":2,"name":"Our Crypto Talk — Bankr Wallets Compromised as $170K Drained on Base","type":"news_article","url":"https://ourcryptotalk.com/news/bankr-wallets-compromised-170k-drained-base"},{"credibility":2,"name":"Yahoo Finance — Bankr Joins May Hack Wave With 14 Wallets Breached","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/bankr-joins-may-hack-wave-041512042.html"},{"credibility":2,"name":"KuCoin — Bankr Confirms Wallet Hacks: 14 Wallets Compromised, Trading Paused, Full Compensation Promised","type":"news_article","url":"https://www.kucoin.com/news/flash/bankr-confirms-wallet-hacks-14-wallets-compromised-trading-paused-and-full-compensation-promised"},{"credibility":2,"name":"NeuralTrust — Grok Morse Code Heist: Prompt Injection Meets Excessive Agency","type":"research","url":"https://neuraltrust.ai/blog/grok-morse-code"},{"credibility":2,"name":"Giskard — How Grok Got Prompt-Injected","type":"research","url":"https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet"},{"credibility":2,"name":"FYEO Blog — Morse Code Prompt Injection: How an Attacker Tricked Grok and Bankrbot Out of $200K","type":"research","url":"https://fyeo.io/blog/morse-code-prompt-injection-grok-bankrbot-200k"},{"credibility":2,"name":"Newsorga — Morse code used to bypass AI guardrails in ~$174,000 Grok-linked token theft on Base","type":"news_article","url":"https://newsorga.com/article/grok-bankrbot-morse-code-prompt-injection-174k-drb-theft-base-may-2026"},{"credibility":2,"name":"CryptoDaily — AI Agents in DeFi: Why Automated Wallets Could Increase Smart Contract Risk","type":"news_article","url":"https://cryptodaily.co.uk/2026/06/ai-agents-defi-automated-wallets-smart-contract-risk"},{"credibility":2,"name":"The Block — Bankrbot Ends Grok's Unintentional Token Creation Spree","type":"news_article","url":"https://www.theblock.co/post/346027/bankrbot-ends-groks-unintentional-token-creation-spree-by-disabling-interactions-on-x"},{"credibility":2,"name":"IQ.wiki — Bankr Protocol Overview","type":"research","url":"https://iq.wiki/wiki/bankr"},{"credibility":3,"name":"DEV Community — What the Grok Wallet Drain Teaches Us About AI Agent Permissions","type":"research","url":"https://dev.to/sagaratalatti/what-the-grok-wallet-drain-teaches-us-about-ai-agent-permissions-3mpf"},{"credibility":3,"name":"Pulsechain Nexus — AI Wallet Service Bankr Halts Network After Key Compromise","type":"news_article","url":"https://www.pulsechain.nexus/ai-wallet-service-bankr-halts-network-after-key-compromise/"}],"summary":"Bankr is an AI-powered crypto wallet and trading bot built on the Base network (Ethereum L2), allowing users to trade, swap, and manage funds through natural-language commands on X (Twitter) and Farcaster. In May 2026, the platform suffered two separate security incidents within weeks of each other: a prompt-injection attack exploiting Grok that drained approximately $150,000–$175,000 in DRB tokens, and a distinct key-compromise or session-token breach that affected 14 user wallets and drained an estimated $170,000–$385,000 in total. Bankr publicly committed to reimbursing all affected users, but no confirmed completion of that reimbursement has been documented in available sources as of the investigation date.","timeline":[{"date":"2024-01-01","event":"Bankr launches as an AI-powered crypto trading bot on Farcaster, building on the Base network.","source":"IQ.wiki — Bankr Protocol Overview","source_url":"https://iq.wiki/wiki/bankr"},{"date":"2025-02-01","event":"BankrCoin (BNKR) token launches on Base with a 100 billion token maximum supply.","source":"KuCoin — Deep Dive into Bankr and BankrCoin","source_url":"https://www.kucoin.com/news/articles/a-deep-dive-into-the-ai-agent-bankr-and-its-ecosystem-token-bankrcoin-bnkr"},{"date":"2025-03-01","event":"Grok misinterprets user inputs and unintentionally creates multiple tokens; Bankr disables Grok on X and removes erroneous tokens from DEX pools.","source":"The Block — Bankrbot Ends Grok's Unintentional Token Creation Spree","source_url":"https://www.theblock.co/post/346027/bankrbot-ends-groks-unintentional-token-creation-spree-by-disabling-interactions-on-x"},{"date":"2026-05-04","event":"Attacker sends 'Bankr Club Membership' NFT to Bankr's Grok-linked wallet, escalating its permission tier, then submits a Morse-code encoded transfer instruction via X. Grok decodes the message and Bankrbot executes the transfer of approximately 3 billion DRB tokens (valued at roughly $150,000–$175,000) to the attacker's address on Base.","source":"OECD AI Incidents — Prompt Injection Exploit Drains Grok-Linked Crypto Wallet","source_url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"date":"2026-05-07","event":"SlowMist publishes on-chain analysis classifying the attack as 'AI Agent permission chain abuse.' Breitbart and CryptoTimes cover the incident. SlowMist reports 80–88% of funds were recovered through negotiations.","source":"CryptoTimes — SlowMist Labels Grok AI Bankr Hack a Permission Chain Attack","source_url":"https://www.cryptotimes.io/2026/05/07/slowmist-labels-grok-ai-bankr-hack-a-permission-chain-attack/"},{"date":"2026-05-08","event":"NeuralTrust and Giskard publish independent security analyses mapping the attack to OWASP LLM01 (Prompt Injection) and LLM06 (Excessive Agency).","source":"NeuralTrust — Grok Morse Code Heist","source_url":"https://neuraltrust.ai/blog/grok-morse-code"},{"date":"2026-05-19","event":"Second, distinct security incident begins. An attacker gains signing authority over at least 14 Bankr user wallets, likely via phishing of Privy session tokens or permit signatures. Bankr pauses all transactions at approximately 15:51 GMT. Approximately $170,000–$385,000 is drained across affected wallets.","source":"CryptoTimes — Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets","source_url":"https://www.cryptotimes.io/2026/05/20/bankr-breach-exposes-ai-crypto-wallet-after-attacker-accessed-14-wallets/"},{"date":"2026-05-20","event":"Bankr publicly confirms the second breach, discloses 14 wallets affected, pledges full reimbursement of lost funds, and advises users to generate new wallets and revoke sessions. The BNKR token drops 10–11% on the announcement.","source":"KuCoin — Bankr Confirms Wallet Hacks: 14 Wallets Compromised","source_url":"https://www.kucoin.com/news/flash/bankr-confirms-wallet-hacks-14-wallets-compromised-trading-paused-and-full-compensation-promised"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision ad147118-61ad-4d88-9b8a-e8423d106b3a
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.