T
iTokenly

Banana Gun hack — September 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedSeptember 19, 2024
Target typeWallet software or provider
Loss$3,000,000Published estimates range $1,400,000 to $3,000,000Price at time of incident
MethodInfrastructure compromiseBanana Gun attributed the breach to a vulnerability in the third-party Telegram message oracle its bot relied on to receive and authenticate user commands. An attacker able to intercept those messages could act in the user's place and manually move ETH out of the wallets the bot custodied while victims were mid-session. The bot's own smart contracts were not exploited.
ChainsEthereum, Solana
OutcomeUsers reimbursed

What happened

Banana Gun, a Telegram trading bot that holds wallet keys on behalf of its users, was exploited on 19 September 2024. The bot's Ethereum and Solana instances were both affected despite running on separate codebases, which pointed at a shared component rather than chain-specific code.

Banana Gun attributed the breach to a potential vulnerability in the Telegram message oracle it used. The bot relied on that third-party component to receive and authenticate Telegram messages; according to QuillAudits' analysis, an attacker able to intercept those messages could act in a user's place and issue transfers manually while victims were using the bot, moving ETH out of the custodied wallets. There was no automated contract drain — the bot's own smart contracts were not exploited, and no published account describes a front-end vulnerability. The team described the oracle flaw as potential rather than confirmed, and no independent technical post-mortem of the oracle itself was published.

The reported figures moved as the picture filled in. Early on-chain reporting counted 563 ETH, roughly $1.4 million at prices that day, drained from wallets on Ethereum, with initial counts putting the number of victims at fewer than 50 Telegram accounts and 36 distinct wallets. Banana Gun's own post-mortem later settled on 11 affected users and a total of about $3 million across both the EVM and Solana bots, a figure carried by The Defiant, The Block and QuillAudits, and the reimbursement pledge was framed around that number. The record carries both ends as a range because the reconciliation between the early on-chain count and the project's final total was not published in detail.

Banana Gun took both bots offline immediately, then said all affected users would be fully refunded from the project treasury, with no tokens sold to fund the repayments. QuillAudits' later analysis states the refunds were made. Service resumed with a two-hour delay on transfers and planned two-factor authentication, alongside audit and penetration-testing work with the Security Alliance. The BANANA token fell on the news. No attacker has been named.

Sources

  1. The DefiantSecondary · retrieved 2026-08-01
  2. QuillAuditsSecondary · retrieved 2026-08-01
  3. CoinGapeSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Banana Gun hack — September 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/banana-gun
https://itokenly.com/hacks/banana-gun

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.