Trading bot hacks & security incidents
What failed, how much was lost, and what users got back. A source-by-source record of security incidents at crypto trading bots, terminals and AI agents.
Reported losses · main dataset#H01
$27.4M
Sum of published estimates before refunds. One incident has no public dollar estimate; disputed and adjacent cases sit outside this total.
Source: Scope and calculation
9 incidents · 8 published estimates
What this dataset tells us
83%
Losses linked to key custody
83% of recorded dollar losses come from server or private-key compromises. The DEXX estimate drives most of this share.
Source: I04, I06, I095 / 9
Reported full refunds
5 incidents have a full-refund report. This counts company statements and press reports; it is not an audit of every payout.
Source: I01, I02, I03, I05, I07$21M
The largest recorded incident
DEXX’s initial estimate accounts for 77% of the total. Later reports valued the stolen assets at $30M.
Source: DEXX · I06The incident register
Open a row for the evidence, compensation details and conflicting estimates. Dollar amounts are approximate valuations at the time of the incident.
9 of 9 incidents
#I09TradeWizSolanaReported loss$459,468Server / private keysPartial compensation
What happened
TradeWiz said private keys leaked through the key export feature of its Solana copy-trading product; the attacker emptied the wallets in about two and a half hours.
- Product
- Trading terminal
- Reported loss
- $459,468Bitquery estimate
- Reported scope
- 20,933 walletsSource: Bitquery
Compensation
TradeWiz sent a first wave of refunds on 30 September 2026 and says all verified losses will be fully compensated, each claim checked individually; no completion figure has been published.
Where sources differ
TradeWiz published no loss figure. Other on-chain counts give about $439K across 20,800 wallets, and $375K across 9,580.
Evidence & sources
- TradeWiz — Security notice: private key exposure in the SOL PVP export feature (30 September 2026)Project statement
- TradeWiz — First wave of refunds has been sent (30 September 2026)Project statement
- TradeWiz — Security incident update: reported to police (1 October 2026)Project statement
- Bitquery — TradeWiz hack: the attacker was a customer firstSecurity research
- CrossMeme (TradeWiz statements) — TradeWiz security incident: what happenedIncident tracker
#I08BankrBaseReported loss$170,000Not establishedRefund pledged
What happened
Bankr paused transactions after an attacker moved funds out of 14 Bankr wallets. No cause was published: a hijacked command and leaked credentials both remain possible.
- Product
- AI trading agent
- Reported loss
- $170,000
- Reported scope
- 14 walletsSource: Bankr
Compensation
Bankr said it would reimburse all lost funds; no source confirms the payouts.
Where sources differ
Estimates run from $170K to about $385K.
Evidence & sources
#I07GMGNBSCReported lossNot disclosedMEV protection failureFull refund reported
What happened
GMGN’s anti-sandwich nodes on BSC were bypassed for about 13 hours, and 729 user trades sent through them were sandwiched.
- Product
- Trading terminal
- Reported loss
- Not disclosed
- Reported scope
- 729 transactionsSource: GMGN
Compensation
GMGN credited compensation to the affected wallets the next day. No amount was published in the sources checked.
Evidence & sources
#I06DEXXSolana · EthereumReported loss$21,000,000Server / private keysPartial compensation
What happened
DEXX stored users’ private keys on its servers. SlowMist traced the breach to a vulnerable project-management platform that gave the attacker server and database access.
- Product
- Trading terminal
- Reported loss
- $21,000,000
- Reported scope
- at least 900 usersSource: SlowMist
Compensation
A compensation process and a $15M pledge led by LBank started paying victims by February 2025, while the largest victims were still negotiating.
Where sources differ
SlowMist later put the total at $30M as token prices moved. Users first alleged insider theft; SlowMist’s review found an outside intrusion.
Evidence & sources
- ChainCatcher (SlowMist) — The DEXX incident has confirmed over 900 victims (18 November 2024)Reporting
- ChainCatcher (SlowMist) — DEXX theft confirmed as an external attack (26 March 2025)Reporting
- FinanceFeeds — 8,600 Solana addresses linked to DEXX hackReporting
- Odaily — Is the DEXX theft incident coming to an end?Reporting
#I05Banana GunEthereum · SolanaReported loss$3,000,000Command authenticationFull refund reported
What happened
A flaw in the third-party Telegram message oracle Banana Gun used to authenticate commands let an attacker move ETH out of 11 users’ wallets while they traded.
- Product
- Telegram bot
- Reported loss
- $3,000,000
- Reported scope
- 11 usersSource: Banana Gun
Compensation
Banana Gun refunded all 11 users from its treasury within a week, without selling tokens to pay for it.
Where sources differ
Early on-chain counts said 563 ETH across 36 wallets; the post-mortem settled on 11 users and $3M.
Evidence & sources
#I04SolareumSolanaReported loss$1,400,000Server / private keysNo payout reported
What happened
Solareum kept users’ private keys on its own servers. A January 2025 US court filing says a developer it had hired, working for North Korea, used that access to drain the wallets.
- Product
- Telegram bot
- Reported loss
- $1,400,0006,045 SOL
- Reported scope
- at least 300 usersSource: Decrypt
Compensation
Solareum shut down on 30 March 2024 without a compensation plan. About $950K in USDT was seized later; no payout to victims has been reported.
Where sources differ
Early reports said $523K. The court filing names only “US Company 1”; the link to Solareum comes from DL News reporting.
Evidence & sources
#I03Thunder TerminalEthereum · SolanaReported loss$240,000Session tokensFull refund reported
What happened
An attacker used a leaked MongoDB connection and session tokens to send withdrawals that Thunder’s servers treated as authorised.
- Product
- Trading terminal
- Reported loss
- $240,00086.5 ETH and 439 SOL
- Reported scope
- 114 walletsSource: Thunder Terminal
Compensation
Thunder said on 28 December 2023 that every affected user had been compensated in full. The company’s own statement is the only confirmation, relayed by press; no on-chain proof of the payouts was found.
Where sources differ
The same 28 December statement, as relayed by PANews/CoinNess, gives an average loss of $223, which does not add up to its own $240K total.
Evidence & sources
#I02UnibotEthereumReported loss$640,000Router / token approvalsFull refund reported
What happened
Unibot’s new router, deployed three days earlier, accepted arbitrary calls, so the attacker pulled the tokens users had approved to it.
- Product
- Telegram bot
- Reported loss
- $640,000355.75 ETH
- Reported scope
- about 600 walletsSource: Crypto Times
Compensation
Unibot compensated affected users and closed the incident on 2 November 2023; Crypto Times put the cost at $1.78M.
Where sources differ
Some early coverage said $560K. DefiLlama still lists no funds returned.
Evidence & sources
- CoinDesk — Unibot token hurtles 25% as Telegram bot exploitedReporting
- CertiK — Maestro & UnibotSecurity research
- Crypto Times — Unibot reimburses users following security hack (4 November 2023)Reporting
- Revoke.cash — 2023 Unibot hackIncident tracker
#I01MaestroEthereumReported loss$500,000Router / token approvalsFull refund reported
What happened
A flaw in Maestro’s Router 2 contract let the attacker pull tokens that users had approved to it and swap them for ETH.
- Product
- Telegram bot
- Reported loss
- $500,000280 ETH taken
- Reported scope
- 106 usersSource: CertiK
Compensation
Refunded within about 10 hours from Maestro’s revenue: 610 ETH spent buying the tokens back or paying their value plus 20%.
Where sources differ
DefiLlama dates it 23 October. The 610 ETH often quoted as the loss is what the refund cost.
Evidence & sources
- Maestro — Wrapping up the exploit sagaProject statement
- CertiK — Maestro & UnibotSecurity research
- The Block — Maestro Telegram bot suffers a contract exploitReporting
- Revoke.cash — 2023 Maestro hackIncident tracker
Where the recorded losses came from
Each incident has one primary failure category. Bars show gross reported losses; unpriced incidents are counted but add no dollar value.
- Server / private keys$22.9M3 incidents · Solareum, DEXX, TradeWiz
- Command authentication$3M1 incidents · Banana Gun
- Router / token approvals$1.14M2 incidents · Maestro, Unibot
- Session tokens$240K1 incidents · Thunder Terminal
- Not established$170K1 incidents · Bankr
- MEV protection failureNot disclosed1 incidents · GMGN
Losses by year
This is a curated historical sample, not an estimate of all hacks in the market. 2026 covers incidents found through the review date.
- 2023$1.38M3 incidents · I01, I02, I03
- 2024$25.4M3 incidents · I04, I05, I06
- 2025Not disclosed1 incidents · I07
- 2026$629K2 incidents · I08, I09
Sum of selected estimates : $27,409,468. GMGN : not disclosed.
Related cases, outside the total
These cases help explain the risks around bots, but fail the main dataset’s scope or evidence test. They are included in the CSV with in_totals = no.
#E01DogWifToolsSolanaReported loss$10,000,000Compromised software updateUnknown
Why excluded from the total. A token-launch and volume tool rather than a trading bot, and the $10M estimate was disputed and not established.
What happened
Trojanized Windows builds of the tool stole the private keys stored on users’ computers.
- Product
- Token-launch tool
- Reported loss
- $10,000,000disputed estimate
Compensation
No compensation reported.
Evidence & sources
#E02Mithril Trading BotParadexReported loss$0API key exposureNo loss to refund
Why excluded from the total. No funds were lost: the exposed subkeys could trade but not withdraw.
What happened
An attacker reached Mithril’s internal systems and obtained about 57 Paradex trading subkeys; Paradex revoked them.
- Product
- Perps trading bot (Paradex)
- Reported loss
- $0
- Reported scope
- about 57 API subkeysSource: Paradex
Compensation
No funds lost.
Evidence & sources
#E03BankrBaseReported loss$174,000Prompt injectionPartial compensation
Why excluded from the total. The drained wallet was the one Bankr provisioned for Grok’s account, not a trader’s.
What happened
A Morse-coded message that xAI’s Grok decoded and reposted was taken by Bankr as a valid command, and it sent 3 billion DRB from the wallet Bankr had created for Grok.
- Product
- AI trading agent
- Reported loss
- $174,0003 billion DRB
Compensation
About 80% came back after the attacker was identified.
Evidence & sources
#E04BankrBaseReported loss$479,885Account takeoverUnknown
Why excluded from the total. The drained wallet was linked to the project, Bankr says its product was not breached, and no loss from users’ wallets is established.
What happened
Bankr lost control of its @bankrbot X account, which posted fake airdrop links, and a project-linked wallet without in-app two-factor protection was emptied.
- Product
- AI trading agent
- Reported loss
- $479,8851.5 billion BNKR
Compensation
No reimbursement announced.
Evidence & sources
- AUTOSEC — Bankr X account takeover: reported $480K drainedSecurity research
- Bankr developer — Locked out of the @bankrbot accountProject statement
#E05LootBotEthereum · BaseReported loss$627,000Server / private keysUnknown
Why excluded from the total. Mostly an airdrop-farming bot, and the 2,442 drained wallets are not its customer list: Bitquery identifies 557 wallets that ever paid LootBot on chain, of which 277 (49.7%) fell in the drained set — 11% of it. Median loss about $26.
What happened
LootBot kept the keys of the wallets it created on its servers; one address emptied 2,442 of them in about 31 hours.
- Product
- Airdrop-farming bot
- Reported loss
- $627,000259 ETH, a floor
- Reported scope
- 2,442 walletsSource: Bitquery
Compensation
No statement from LootBot found in the sources checked.
Evidence & sources
Claims we did not attribute to a trading bot
- BONKbot : denied a breach in March 2024; the drained users had imported their keys into Solareum. Source
- Bloom (DefiLlama, May 2024) : a different project of the same name, a perps protocol on Blast, not the Bloom trading bot. Source
- Sigma (May 2026) : one trader’s $200K loss on two wallets that the report says were created via Sigma and later imported into GMGN and Rabby; it documents a private-key compromise, so a breach on Sigma’s side is plausible but not established. Source
How to read and cite this database
Inclusion requires a named consumer trading tool, an identifiable incident, and credible public evidence of user funds lost through the tool. A failed protection service can qualify without a wallet breach.
- Losses, not net damage
- We add the selected initial loss estimates in USD. Refunds, recovered funds and later token-price changes are not deducted or added. A blank amount means undisclosed; zero is reserved for a confirmed report of no financial loss.
- Evidence before a label
- Project statements, security research and independent reporting are linked on every record. A project’s refund announcement is identified as such. A promise is not classified as a completed refund.
- Wallets are not people
- We preserve the unit the source reports: users, wallets, transactions or API subkeys. These counts are never added together or treated as unique victims across products.
- A curated record, not a safety ranking
- Coverage starts in 2023 and is not exhaustive. Product age, activity and disclosure practices differ, so incident counts cannot measure the probability of being hacked. Absence from this list does not establish safety.
- Updates and corrections
- Records are reviewed manually. The review date is the date we checked the cited material, not necessarily the date of its latest statement. New evidence can change an estimate or refund status; stable incident IDs remain the same.
Reuse the data
The CSV contains the main register and related cases, with inclusion flags, original source URLs and review dates. Cite a specific incident for a claim, or this page for an aggregate; keep the scope and uncertainty attached.
CSV · 14 records · English field names
DegenBench. “Trading bot hacks & security incidents.” Sources reviewed 7 October 2026. https://degenbench.com/en/data/trading-bot-hacks