Certain users of Banana Gun had reported unauthorized outgoing transfers from their cryptocurrency wallets on September 19, 2024. As a result, the platform had to disable its Ethereum Virtual Machine (EVM) temporarily, and Solana bots to prevent additional losses.
The initial findings indicated that 36 users were impacted by the breach and lost around $2 million worth of Ether (ETH). However, a subsequent Banana Gun report revealed that the number of affected users was 11, with a total loss of $3 million. Banana Gun has pledged to fully refund all affected users from its treasury without resorting to selling tokens for refunds.
BOT INCIDENT RECAP
First of all, we’re humbled by the incredible bot activity on Banana Gun, even after last week’s incident. Thank you all for your patience and trust. We take this as a testament that we’re handling the situation properly. As previously mentioned, our EVM and…
— Banana Gun ???????? (@BananaGunBot) September 24, 2024
Banana Gun team addresses the hack
The project’s team has verified that an issue with its trading bot affected experienced crypto traders due to a vulnerability. Unauthorized manual transfers and notifications within the bot raised concerns that a hacker took advantage of a vulnerability in a Telegram message oracle.
The attacker focused on experienced cryptocurrency traders and was able to manually transfer ETH from their wallets while they were using trading bots, unlike typical hackers who target inexperienced investors.
After addressing the security vulnerability, Banana Gun rebooted the EVM and Solana bots and implemented additional security protocols to prevent future fund depletion. These measures consist of a two-hour transfer hold, two-factor authentication for transfers, and a comprehensive system review, among other steps.
In a similar development on May 10, 2024, a scammer involved in a poisoning scam resulting in loss of $71 million worth of Wrapped Bitcoin (WBTC) initiated contact with the victim through Telegram. The scammer offered to return 50% of the stolen funds. Peckshield, an on-chain security firm, disclosed that the scammer had taken a surprising step by sending 51 ETH to the victim, accompanied by a message soliciting communication via Telegram.
Also Read:Taiko Halts Bridge Operations After $1.7 Million Exploit
The platform relaunched after the exploit
Banana Gun eventually returned to operation after reviewing and rebuilding the affected infrastructure.
The project continued developing its Telegram-based trading bot and expanded its supported chains and trading features. Its model allows users to execute trades, set automated orders and monitor positions directly from Telegram rather than switching between multiple applications.
The recovery demonstrated an important distinction between a blockchain exploit and a failure in an application built on top of it. Ethereum itself was not compromised during the Banana Gun attack. The vulnerability existed within Banana Gun’s own smart-contract and wallet infrastructure.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.
























































































