Telegram Message-Oracle Flaw Drains $3 Million From Banana Gun Traders
Banana Gun, a Telegram-based crypto trading bot marketed as secure, suffered a wallet-draining exploit on September 19 that ultimately cost users roughly $3 million.
The first public signal came from a trader known as Yannick Crypto, who posted early rumors that Banana Gun wallets were being drained and that the true number of victims might be larger than known at the time: "There is rumour that Banana Gun wallet's getting drained right now. But there is rumour that there are much more victims."

Initial estimates put the damage at $1.9 million spread across 36 users. As more information came in, the figures shifted: the confirmed total settled at 11 victims with combined losses of about $3 million — a smaller group of people hit for considerably larger individual sums.
Banana Gun subsequently disclosed that the attacker had exploited a previously unknown vulnerability in the bot's Telegram message oracle, affecting both its Ethereum and Solana versions. The team responded by shutting down both the Ethereum and Solana bots.
The attack appears to have been targeted rather than opportunistic, focusing specifically on smart-money traders and other recognizable figures in the space — accounts with some degree of public visibility through social media presence or trading track record. According to reports, victims watched in real time as the attacker manually transferred ETH out of their wallets.
In its incident report, Banana Gun outlined a set of security measures — two-factor authentication, transfer delays, and a broader system review — that had evidently not been fully in place before the incident. The team also pledged full refunds to affected users, to be paid from the project's treasury without any token sales. Banana Gun described the root cause simply as a "potential vulnerability in the Telegram message oracle."

The same day brought reports of comparable incidents at two other Telegram-based trading bots. Maestro Bot reportedly lost about $200,000 to a suspicious wallet, while Unibot acknowledged an "ongoing exploit." Neither bot published a detailed incident report afterward; Maestro Bot instead downplayed the concern, stating, "We haven't received 1 single complaint from any of our users getting their funds stolen."
Whether the near-simultaneous incidents across the three bots were coordinated or coincidental remains unclear. The episode nonetheless raises broader questions about the security of Telegram as an infrastructure layer for crypto trading bots — a fast-growing product category that may now face closer scrutiny over vulnerabilities shared across platforms built on the same messaging service.
Get new scam files the moment we publish them — usually 2–3 emails a week.