Trading bot hacks & security incidents

What failed, how much was lost, and what users got back. A source-by-source record of security incidents at crypto trading bots, terminals and AI agents.

Sources reviewed 7 October 2026 · 2023–2026

Reported losses · main dataset#H01

$27.4M

Sum of published estimates before refunds. One incident has no public dollar estimate; disputed and adjacent cases sit outside this total.

Source: Scope and calculation

9 incidents · 8 published estimates

What this dataset tells us

83%

Losses linked to key custody

83% of recorded dollar losses come from server or private-key compromises. The DEXX estimate drives most of this share.

Source: I04, I06, I09

5 / 9

Reported full refunds

5 incidents have a full-refund report. This counts company statements and press reports; it is not an audit of every payout.

Source: I01, I02, I03, I05, I07

$21M

The largest recorded incident

DEXX’s initial estimate accounts for 77% of the total. Later reports valued the stolen assets at $30M.

Source: DEXX · I06

The incident register

Open a row for the evidence, compensation details and conflicting estimates. Dollar amounts are approximate valuations at the time of the incident.

9 of 9 incidents

#I09TradeWizSolanaReported loss$459,468Server / private keysPartial compensation

What happened

TradeWiz said private keys leaked through the key export feature of its Solana copy-trading product; the attacker emptied the wallets in about two and a half hours.

Product
Trading terminal
Reported loss
$459,468Bitquery estimate
Reported scope
20,933 walletsSource: Bitquery

Compensation

TradeWiz sent a first wave of refunds on 30 September 2026 and says all verified losses will be fully compensated, each claim checked individually; no completion figure has been published.

Where sources differ

TradeWiz published no loss figure. Other on-chain counts give about $439K across 20,800 wallets, and $375K across 9,580.

#I08BankrBaseReported loss$170,000Not establishedRefund pledged

What happened

Bankr paused transactions after an attacker moved funds out of 14 Bankr wallets. No cause was published: a hijacked command and leaked credentials both remain possible.

Product
AI trading agent
Reported loss
$170,000
Reported scope
14 walletsSource: Bankr

Compensation

Bankr said it would reimburse all lost funds; no source confirms the payouts.

Where sources differ

Estimates run from $170K to about $385K.

#I07GMGNBSCReported lossNot disclosedMEV protection failureFull refund reported

What happened

GMGN’s anti-sandwich nodes on BSC were bypassed for about 13 hours, and 729 user trades sent through them were sandwiched.

Product
Trading terminal
Reported loss
Not disclosed
Reported scope
729 transactionsSource: GMGN

Compensation

GMGN credited compensation to the affected wallets the next day. No amount was published in the sources checked.

#I06DEXXSolana · EthereumReported loss$21,000,000Server / private keysPartial compensation

What happened

DEXX stored users’ private keys on its servers. SlowMist traced the breach to a vulnerable project-management platform that gave the attacker server and database access.

Product
Trading terminal
Reported loss
$21,000,000
Reported scope
at least 900 usersSource: SlowMist

Compensation

A compensation process and a $15M pledge led by LBank started paying victims by February 2025, while the largest victims were still negotiating.

Where sources differ

SlowMist later put the total at $30M as token prices moved. Users first alleged insider theft; SlowMist’s review found an outside intrusion.

#I05Banana GunEthereum · SolanaReported loss$3,000,000Command authenticationFull refund reported

What happened

A flaw in the third-party Telegram message oracle Banana Gun used to authenticate commands let an attacker move ETH out of 11 users’ wallets while they traded.

Product
Telegram bot
Reported loss
$3,000,000
Reported scope
11 usersSource: Banana Gun

Compensation

Banana Gun refunded all 11 users from its treasury within a week, without selling tokens to pay for it.

Where sources differ

Early on-chain counts said 563 ETH across 36 wallets; the post-mortem settled on 11 users and $3M.

#I04SolareumSolanaReported loss$1,400,000Server / private keysNo payout reported

What happened

Solareum kept users’ private keys on its own servers. A January 2025 US court filing says a developer it had hired, working for North Korea, used that access to drain the wallets.

Product
Telegram bot
Reported loss
$1,400,0006,045 SOL
Reported scope
at least 300 usersSource: Decrypt

Compensation

Solareum shut down on 30 March 2024 without a compensation plan. About $950K in USDT was seized later; no payout to victims has been reported.

Where sources differ

Early reports said $523K. The court filing names only “US Company 1”; the link to Solareum comes from DL News reporting.

#I03Thunder TerminalEthereum · SolanaReported loss$240,000Session tokensFull refund reported

What happened

An attacker used a leaked MongoDB connection and session tokens to send withdrawals that Thunder’s servers treated as authorised.

Product
Trading terminal
Reported loss
$240,00086.5 ETH and 439 SOL
Reported scope
114 walletsSource: Thunder Terminal

Compensation

Thunder said on 28 December 2023 that every affected user had been compensated in full. The company’s own statement is the only confirmation, relayed by press; no on-chain proof of the payouts was found.

Where sources differ

The same 28 December statement, as relayed by PANews/CoinNess, gives an average loss of $223, which does not add up to its own $240K total.

#I02UnibotEthereumReported loss$640,000Router / token approvalsFull refund reported

What happened

Unibot’s new router, deployed three days earlier, accepted arbitrary calls, so the attacker pulled the tokens users had approved to it.

Product
Telegram bot
Reported loss
$640,000355.75 ETH
Reported scope
about 600 walletsSource: Crypto Times

Compensation

Unibot compensated affected users and closed the incident on 2 November 2023; Crypto Times put the cost at $1.78M.

Where sources differ

Some early coverage said $560K. DefiLlama still lists no funds returned.

#I01MaestroEthereumReported loss$500,000Router / token approvalsFull refund reported

What happened

A flaw in Maestro’s Router 2 contract let the attacker pull tokens that users had approved to it and swap them for ETH.

Product
Telegram bot
Reported loss
$500,000280 ETH taken
Reported scope
106 usersSource: CertiK

Compensation

Refunded within about 10 hours from Maestro’s revenue: 610 ETH spent buying the tokens back or paying their value plus 20%.

Where sources differ

DefiLlama dates it 23 October. The 610 ETH often quoted as the loss is what the refund cost.

Where the recorded losses came from

Each incident has one primary failure category. Bars show gross reported losses; unpriced incidents are counted but add no dollar value.

  1. Server / private keys$22.9M
    3 incidents · Solareum, DEXX, TradeWiz
  2. Command authentication$3M
    1 incidents · Banana Gun
  3. Router / token approvals$1.14M
    2 incidents · Maestro, Unibot
  4. Session tokens$240K
    1 incidents · Thunder Terminal
  5. Not established$170K
    1 incidents · Bankr
  6. MEV protection failureNot disclosed
    1 incidents · GMGN

Losses by year

This is a curated historical sample, not an estimate of all hacks in the market. 2026 covers incidents found through the review date.

  1. 2023$1.38M
    3 incidents · I01, I02, I03
  2. 2024$25.4M
    3 incidents · I04, I05, I06
  3. 2025Not disclosed
    1 incidents · I07
  4. 2026$629K
    2 incidents · I08, I09

Sum of selected estimates : $27,409,468. GMGN : not disclosed.

These cases help explain the risks around bots, but fail the main dataset’s scope or evidence test. They are included in the CSV with in_totals = no.

#E01DogWifToolsSolanaReported loss$10,000,000Compromised software updateUnknown

Why excluded from the total. A token-launch and volume tool rather than a trading bot, and the $10M estimate was disputed and not established.

What happened

Trojanized Windows builds of the tool stole the private keys stored on users’ computers.

Product
Token-launch tool
Reported loss
$10,000,000disputed estimate

Compensation

No compensation reported.

#E02Mithril Trading BotParadexReported loss$0API key exposureNo loss to refund

Why excluded from the total. No funds were lost: the exposed subkeys could trade but not withdraw.

What happened

An attacker reached Mithril’s internal systems and obtained about 57 Paradex trading subkeys; Paradex revoked them.

Product
Perps trading bot (Paradex)
Reported loss
$0
Reported scope
about 57 API subkeysSource: Paradex

Compensation

No funds lost.

#E03BankrBaseReported loss$174,000Prompt injectionPartial compensation

Why excluded from the total. The drained wallet was the one Bankr provisioned for Grok’s account, not a trader’s.

What happened

A Morse-coded message that xAI’s Grok decoded and reposted was taken by Bankr as a valid command, and it sent 3 billion DRB from the wallet Bankr had created for Grok.

Product
AI trading agent
Reported loss
$174,0003 billion DRB

Compensation

About 80% came back after the attacker was identified.

#E04BankrBaseReported loss$479,885Account takeoverUnknown

Why excluded from the total. The drained wallet was linked to the project, Bankr says its product was not breached, and no loss from users’ wallets is established.

What happened

Bankr lost control of its @bankrbot X account, which posted fake airdrop links, and a project-linked wallet without in-app two-factor protection was emptied.

Product
AI trading agent
Reported loss
$479,8851.5 billion BNKR

Compensation

No reimbursement announced.

#E05LootBotEthereum · BaseReported loss$627,000Server / private keysUnknown

Why excluded from the total. Mostly an airdrop-farming bot, and the 2,442 drained wallets are not its customer list: Bitquery identifies 557 wallets that ever paid LootBot on chain, of which 277 (49.7%) fell in the drained set — 11% of it. Median loss about $26.

What happened

LootBot kept the keys of the wallets it created on its servers; one address emptied 2,442 of them in about 31 hours.

Product
Airdrop-farming bot
Reported loss
$627,000259 ETH, a floor
Reported scope
2,442 walletsSource: Bitquery

Compensation

No statement from LootBot found in the sources checked.

Claims we did not attribute to a trading bot

  • BONKbot : denied a breach in March 2024; the drained users had imported their keys into Solareum. Source
  • Bloom (DefiLlama, May 2024) : a different project of the same name, a perps protocol on Blast, not the Bloom trading bot. Source
  • Sigma (May 2026) : one trader’s $200K loss on two wallets that the report says were created via Sigma and later imported into GMGN and Rabby; it documents a private-key compromise, so a breach on Sigma’s side is plausible but not established. Source

How to read and cite this database

Inclusion requires a named consumer trading tool, an identifiable incident, and credible public evidence of user funds lost through the tool. A failed protection service can qualify without a wallet breach.

Losses, not net damage
We add the selected initial loss estimates in USD. Refunds, recovered funds and later token-price changes are not deducted or added. A blank amount means undisclosed; zero is reserved for a confirmed report of no financial loss.
Evidence before a label
Project statements, security research and independent reporting are linked on every record. A project’s refund announcement is identified as such. A promise is not classified as a completed refund.
Wallets are not people
We preserve the unit the source reports: users, wallets, transactions or API subkeys. These counts are never added together or treated as unique victims across products.
A curated record, not a safety ranking
Coverage starts in 2023 and is not exhaustive. Product age, activity and disclosure practices differ, so incident counts cannot measure the probability of being hacked. Absence from this list does not establish safety.
Updates and corrections
Records are reviewed manually. The review date is the date we checked the cited material, not necessarily the date of its latest statement. New evidence can change an estimate or refund status; stable incident IDs remain the same.

Reuse the data

The CSV contains the main register and related cases, with inclusion flags, original source URLs and review dates. Cite a specific incident for a claim, or this page for an aggregate; keep the scope and uncertainty attached.

Download the database

CSV · 14 records · English field names

Suggested citation

DegenBench. “Trading bot hacks & security incidents.” Sources reviewed 7 October 2026. https://degenbench.com/en/data/trading-bot-hacks