Your use of the term "relapse" completely undermines your argument. A relapse isn't a technical glitch on the bank's part, but a conscious decision against your own intentions. Someone who actively clicks "Confirm" 250 times (!) in their app isn't acting helplessly, but with full intent.
But since you're so insistent on the bank's duty of care, I have a very simple question for you – and that's exactly the question the ombudsman will ask you:
If you specifically chose this bank because it 'strictly blocks' gambling: Why didn't you contact the bank immediately after your very first successful deposit to point out the loophole in the system?
If you didn't report it, you didn't want any protection at all. You wanted to exploit the loophole in System 249 more times. That's called 'bad faith'.
If you claim you couldn't report it because you were 'trapped', then you are admitting that you consciously recognized the transactions as gambling – while the bank only saw a fake code (MCC).
So you were fully aware of the situation; the bank was blinded by the casino's fraud. You didn't use the system as a shield, but as a scapegoat in case you lost.
To be clear: You actively confirmed a contract 250 times and used a service. Now that the money's gone, the bank should foot the bill. Save yourself the postage for the ombudsman. Anyone who identifies a security vulnerability and relentlessly exploits it for €15,000 has forfeited any right to 'due diligence'. You got what you ordered. Take responsibility for it.
Automatic translation: