$3 000 000 USD

SEPTEMBER 2024

GLOBAL

BANANA GUN

DESCRIPTION OF EVENTS

"TRADE CRYPTO THE BANANA WAY"

 

"Welcome to Banana Gun, YOUR trading bot. Available on Telegram and soon our own webapp. Snipe upcoming launches or safely trade tokens that are already live. We are your go-to platform for trading on the Ethereum, Solana, Base and Blast chains (with more to come!)."

 

"The best trading bot on Ethereum, Solana, Base and Blast. Built by on-chain traders."

 

"Initially reported as a $1.9M slipup affecting 36 users, this bunch of bad news eventually grew to a $3M whopper impacting 11 very unhappy campers."

 

"There is rumour that @BananaGunBot wallet's getting drained right now. Recipient of the 6 drained wallets i could find is 0xe451241389b80a980c44dd55805eb05276cd141c 0xd073f28400be60aae6691d6131b5f7f45e91d999 But there is rumour that there are much more victims."

 

"Seems like there is already 36 victims with almost 563 #ETH stolen "so far" on mainnet. The last one was drained an hour ago, but there is more rumour that drains started on #SOL too."

 

ZekeEther: "is @BananaGunBot hacked?

 

my wallet is out $15k, completely drained. trying to check onchain transaction but TG bot is also not working.

 

gosh, how much worse can one life fucking get!"

 

Mduz_NFT: "Did anyone else got drain for 50k from @BananaGunBot?

 

Please tell me I'm dreaming."

 

"@BananaGunBot has reportedly been exploited with wallet draining incidents. Users should temporarily move all funds to ensure that they are safe - sheesh!"

 

"Transfer all your funds from telegram trading bots. Already seen lots of drained wallet messages about @BananaGunBot. Do not use any tg trading bots for now."

 

"As one of the few victims, I individually lost 128e on the exploit while I was asleep. They targetted a few specific ppl, honestly one of the most bizarre hacks I've ever seen.

 

Thankfully, the Banana team is goated, and I'll be seeing my funds again soon. Will keep using"

 

"Today, some users of Banana Gun experienced unauthorized transfers from their wallets. Promptly after the first incident, we immediately switched off the bot and began diligently checking our back-end.

 

We have confirmed that our back-end is not compromised. Both the router and database have been thoroughly inspected, and only a very small number of users (fewer than 10) were affected. Additionally, the transfers appear to have been executed manually.

 

This leads us to believe the issue may stem from a front-end vulnerability.

 

As we prioritize security, we will keep our bot offline while we investigate the root cause. The amount of support we've received, particularly from our partners, has been truly heartwarming. If you have any insights that may help us, feel free to send us a direct message here on Twitter."

 

"First of all, we’re humbled by the incredible bot activity on Banana Gun, even after last week’s incident. Thank you all for your patience and trust. We take this as a testament that we're handling the situation properly. As previously mentioned, our EVM and Solana bots are back online with no restrictions, except for a 2-hour transfer delay.

 

A total of 11 users were affected, with $3M drained. All impacted users will be fully refunded from the Banana Gun treasury, with no tokens being sold for reimbursements."

Banana Gun is a Telegram-based trading bot. On September 19th, 2024, multiple high-profile users started reporting their funds being drained from their wallets, live in front of them. While full details of the vulnerability have not yet been released, it is believed to be a vulnerability in the Telegram messaging system. 2FA on withdrawals, and a 2 hour delay, were both implemented in response. Users who were affected have reportedly all been reimbursed.

Rekt - Banana Gun - Rekt (Sep 26)
@BananaGunBot Twitter (Sep 26)
@YannickCrypto Twitter (Sep 26)
@YannickCrypto Twitter (Sep 26)
@YannickCrypto Twitter (Sep 26)
@BananaGunBot Twitter (Sep 26)
@RektHQ Twitter (Sep 26)
@Sheesh_On_Eth Twitter (Sep 26)
@CryoFrosty Twitter (Sep 26)
@befreeshcrypto Twitter (Sep 26)
@ArbitrageScan Twitter (Sep 26)
Personal Account | Arbitrage Scanner (Sep 26)
@thesheikhcrypto Twitter (Sep 26)
@defi_ant_degen Twitter (Sep 26)
@TheCryptoChefX Twitter (Sep 26)
@SwiatKrypto Twitter (Sep 26)
@fud_and_cry Twitter (Sep 26)
@Solidstarforlyf Twitter (Sep 26)
@PetitPrinceETH Twitter (Sep 26)
@PastanagaCrypto Twitter (Sep 26)
@ZekeEther Twitter (Sep 26)
@Mduz_NFT Twitter (Sep 26)
@HRS_777 Twitter (Sep 26)
@Tawkcrypto Twitter (Sep 26)
@AltcoinsFrance Twitter (Sep 26)
@Web3France_fr Twitter (Sep 26)
@Charlie_Gems Twitter (Sep 26)
@pnldailyy Twitter (Sep 26)
@CryptoBullEye Twitter (Sep 26)
@EzMoneyGems Twitter (Sep 26)
@living_life_9 Twitter (Sep 26)
@cryptocevo Twitter (Sep 26)
@WawKasem Twitter (Sep 26)
@Gotham_New Twitter (Sep 26)
@Gotham_New Twitter (Sep 26)
@Gotham_New Twitter (Sep 26)
@Gotham_New Twitter (Sep 26)
@IBendCrypto Twitter (Sep 26)
@ManaMoonNFT Twitter (Sep 26)
@stacy_muur Twitter (Sep 26)
@Alaouicapital Twitter (Sep 26)
@MaestroBots Twitter (Sep 26)
@razvaneth Twitter (Sep 26)
@denisventures Twitter (Sep 26)
@Gotham_New Twitter (Sep 26)
@daze05xx Twitter (Sep 26)
@Talesofthechain Twitter (Sep 26)
@APederzoli Twitter (Sep 26)
@Gotham_New Twitter (Sep 26)
@MCMongX Twitter (Sep 26)
@HidalgoEric90 Twitter (Sep 26)
@BotfatherTG Twitter (Sep 26)
@MCMongX Twitter (Sep 26)
@beincrypto_es Twitter (Sep 26)
@Mamuduwill66845 Twitter (Sep 26)
@ForkLog Twitter (Sep 26)
@ABMedia_Crypto Twitter (Sep 26)
@LeButineur_Off Twitter (Sep 26)
@thepumpengine Twitter (Sep 26)
@6ft6ETH Twitter (Sep 26)
@0xdodonews Twitter (Sep 26)
@dippy_eth Twitter (Sep 26)
@KriptoAirdropTG Twitter (Sep 26)
@tritonsniperio Twitter (Sep 26)
@MCMongX Twitter (Sep 26)
@CapGemz Twitter (Sep 26)
@matty4188 Twitter (Sep 26)
@cybertech_pro01 Twitter (Sep 26)
@MrBeanCaller Twitter (Sep 26)
@mywebacy Twitter (Sep 26)
@ICODrops Twitter (Sep 26)
@protectmywallet Twitter (Sep 26)
@hackless_defi Twitter (Sep 26)
@CryptoGrayWolf Twitter (Sep 26)
@CryptopepperP Twitter (Sep 26)
@ProdigyTradeBot Twitter (Sep 26)
@boot2thrill Twitter (Sep 26)
@hodooi Twitter (Sep 26)
@Modern_Spider Twitter (Sep 26)
@ForkDAOes Twitter (Sep 26)
@jikan_talakawa Twitter (Sep 26)
@ZoOoOoOM89 Twitter (Sep 26)
@cryptonews Twitter (Sep 26)
@DefiantNews Twitter (Sep 26)
@young_Cryptoo Twitter (Sep 26)
@ChadCaff Twitter (Sep 26)
@respit_ Twitter (Sep 26)
@GL_Capital_ Twitter (Sep 26)
@0xImmortal_ Twitter (Sep 26)
@MCMongX Twitter (Sep 26)
@sicentsoicentsi Twitter (Sep 26)
@tritonsniperio Twitter (Sep 26)
@WenTV_io Twitter (Sep 26)
@BananaBananko24 Twitter (Sep 26)
@CashIsTrash_ Twitter (Sep 26)
@GL_Capital_ Twitter (Sep 26)
@metasolanabot Twitter (Sep 26)
@PablojSojo Twitter (Sep 26)
@TheJs7one Twitter (Sep 26)
@hellosuoha Twitter (Sep 26)
@spyflips Twitter (Sep 26)
@iCryptoGuardian Twitter (Sep 26)
@KriptoAirdropTG Twitter (Sep 26)
@OdailyChina Twitter (Sep 26)
@spyflips Twitter (Sep 26)
@pierarmy_eth Twitter (Sep 26)
@ghostdog3333 Twitter (Sep 26)
@CryptolandOffi1 Twitter (Sep 26)
@Crypto_D00M Twitter (Sep 26)
@BananaGunBot Twitter (Sep 26)
Trade Crypto the Banana Way | Banana Gun (Sep 26)

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.