{"id":94710,"date":"2024-09-25T08:08:51","date_gmt":"2024-09-25T12:08:51","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=94710"},"modified":"2024-09-25T08:08:59","modified_gmt":"2024-09-25T12:08:59","slug":"telegram-bot-banana-gun-to-absorb-3m-hack-loss","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/telegram-bot-banana-gun-to-absorb-3m-hack-loss\/","title":{"rendered":"Telegram Bot Banana Gun to Absorb $3M Hack Loss"},"content":{"rendered":"\n<p>The breach on Banana Gun reported on September 19 forced the company to suspend its Ethereum Virtual Machine (EVM) and Solana bots. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"927\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/1__3HGIp5flt6o6Gi09vMkFw-1024x927.png\" alt=\"Telegram Bot Banana Gun to Absorb $3M Hack Loss\" class=\"wp-image-94718\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/1__3HGIp5flt6o6Gi09vMkFw-1024x927.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/1__3HGIp5flt6o6Gi09vMkFw-300x272.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/1__3HGIp5flt6o6Gi09vMkFw-768x695.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/1__3HGIp5flt6o6Gi09vMkFw-860x778.png 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/1__3HGIp5flt6o6Gi09vMkFw-1320x1195.png 1320w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/1__3HGIp5flt6o6Gi09vMkFw.png 1400w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Telegram Bot Banana Gun to Absorb $3M Hack Loss<\/figcaption><\/figure>\n\n\n\n<p>In response to a recent breach that was carried out by eleven individuals, the cryptocurrency trading bot known as <a href=\"https:\/\/coinscreed.com\/staging\/telegram-bot-banana-gun-relaunches-on-uniswap-v2.html\" data-type=\"post\" data-id=\"59393\">Banana Gun<\/a>, which is based on Telegram has announced that it will reimburse consumers who lost a total of three million dollars.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Banana Gun Looses $3 Million <\/h2>\n\n\n\n<p>Members of the banana gun community claimed on September 19 that unlawful outbound transfers had occurred in their cryptocurrency wallets. The revelation compelled Banana Gun to temporarily disable its Ethereum Virtual Machine (EVM) and Solana bots to prevent any future losses.<\/p>\n\n\n\n<p><a href=\"https:\/\/coinscreed.com\/staging\/solareum-trading-bot-shuts-down-few-days-after-exploit.html\" data-type=\"post\" data-id=\"74991\">Crypto trading bots, <\/a>which cryptocurrency traders frequently use to maximize their profits, make automatic trades possible. The initial investigations claimed that the attack hit 36 people and cost them roughly $2 million in Ether.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"529\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bc-b965-773e-aa15-eed98c57f054-1024x529.webp\" alt=\"\" class=\"wp-image-94719\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bc-b965-773e-aa15-eed98c57f054-1024x529.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bc-b965-773e-aa15-eed98c57f054-300x155.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bc-b965-773e-aa15-eed98c57f054-768x397.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bc-b965-773e-aa15-eed98c57f054-860x444.webp 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bc-b965-773e-aa15-eed98c57f054.webp 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Source: Banana Gun<\/figcaption><\/figure>\n\n\n\n<p>However, Banana Gun's post-mortem report revealed a higher loss with fewer casualties.The incident affected eleven users, resulting in a loss of three million dollars.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Vulnerability within Telegram message oracle<\/h2>\n\n\n\n<p>The bot company has stated that it will not sell tokens for reimbursements, and all affected users will receive full refunds from the Banana Gun treasury. The attacker targeted experienced cryptocurrency traders and was able to manually transfer ETH from their wallets. <\/p>\n\n\n\n<p>This is in contrast to the typical practice of hackers who prey on na\u00efve investors. Given that the hacker exploited a vulnerability in a Telegram message oracle, The bot concluded that the hacker was accountable for both the manual illicit transfers and the in-bot alerts triggered by these transactions.<\/p>\n\n\n\n<p>Following the implementation of the patch for the vulnerability, The telegram bot restarted operations for EVM and Solana bots and put in place security measures to prevent further fund leaks. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Negotiating with hacker<\/h2>\n\n\n\n<p>Banana Gun has implemented measures such as a two-hour transfer delay, two-factor authentication, and a thorough system examination. Shezmu, the hacker who stole $5 million from the yield protocol, repaid the majority of the money after accepting a white hat bounty on September 21.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"529\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bd-5136-7fe9-8e08-757cb5275542-1024x529.webp\" alt=\"\" class=\"wp-image-94720\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bd-5136-7fe9-8e08-757cb5275542-1024x529.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bd-5136-7fe9-8e08-757cb5275542-300x155.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bd-5136-7fe9-8e08-757cb5275542-768x397.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bd-5136-7fe9-8e08-757cb5275542-860x444.webp 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019228bd-5136-7fe9-8e08-757cb5275542.webp 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Source: Shezmu<\/figcaption><\/figure>\n\n\n\n<p>When Shezmu discovered a compromise in one of its ShezmuUSD (ShezUSD) stablecoin vaults, the hacker requested the return of ninety percent of the <a href=\"https:\/\/www.google.com\/search?q=Telegram+Bot+Banana+Gun+to+Absorb+%243M+Hack+Loss&oq=Telegram+Bot+Banana+Gun+to+Absorb+%243M+Hack+Loss&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIGCAEQRRg80gEHMzc0ajBqOagCAbACAQ&client=ms-android-xiaomi-terr1-rso2&sourceid=chrome-mobile&ie=UTF-8\" data-type=\"link\" data-id=\"https:\/\/www.google.com\/search?q=Telegram+Bot+Banana+Gun+to+Absorb+%243M+Hack+Loss&oq=Telegram+Bot+Banana+Gun+to+Absorb+%243M+Hack+Loss&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIGCAEQRRg80gEHMzc0ajBqOagCAbACAQ&client=ms-android-xiaomi-terr1-rso2&sourceid=chrome-mobile&ie=UTF-8\" target=\"_blank\" rel=\"noopener\">stolen funds<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> via an onchain message within twenty-four hours.<\/p>\n\n\n\n<p>Shezmu began receiving the stolen Dai tokens into its wallet within a matter of hours. Following the initial return of 282.18 Ether to the protocol, the hacker then proceeded to provide a second refund of 137 Wrapped Ether (WETH).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The breach on Banana Gun reported on September 19 forced the company to suspend its Ethereum Virtual Machine (EVM) and Solana bots. In response to a recent breach that was carried out by eleven individuals, the cryptocurrency trading bot known as Banana Gun, which is based on Telegram has announced that it will reimburse consumers [&hellip;]<\/p>\n","protected":false},"author":62,"featured_media":94718,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[16443,1496,13400],"class_list":["post-94710","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-banana-gun","tag-hack","tag-trading-bot"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/1__3HGIp5flt6o6Gi09vMkFw.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/94710","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/62"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=94710"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/94710\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/94718"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=94710"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=94710"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=94710"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}