Banana Gun Hack

TOTAL LOST $3.0M
Medium Front-end vulnerability ethereum

What happened

On September 19, 2024, Banana Gun suffered a $3M exploit targeting 11 users due to a Telegram message oracle vulnerability. The attacker manually transferred ETH from victims’ wallets while they interacted with the bot.

The attack exploited a vulnerability in Banana Gun’s Telegram message oracle, affecting both EVM and Solana bots, which operate independently. Smart money traders and crypto veterans were specifically targeted, indicating a highly selective attack. The attacker manually transferred ETH from victims’ wallets during live interactions, suggesting a real-time exploit rather than an automated script.

After a thorough investigation, the issue was patched, and enhanced security measures were implemented. No further attacks have been observed since the bot’s reactivation.

Case & protocol details

Classification Protocol Logic / Other / Frontend & Infrastructure
Protocol Type Telegram Bot
Official Website bananagun.io/
Protocol Twitter/X @BananaGunBot

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.