Solana-based memecoin launchpad Bonk.fun reported a security incident in which its main domain was hijacked and a wallet drainer was injected into the site’s frontend, leading to user funds being stolen when they interacted with a fake signature prompt. According to the project and its operator known as Tom / @SolportTom, attackers gained control of a team-associated account tied to domain operations, then modified the website to display a fraudulent “terms of service” (or similar approval) message that, when signed, granted the drainer permission to move assets from victims’ wallets. The project publicly warned users on social media not to visit or interact with the bonk.fun domain until it was secured. Tom and the team stressed that the incident was a frontend/domain compromise, not a smart-contract exploit, meaning past connections to Bonk.fun and trades through third‑party terminals were not affected as long as users did not sign the malicious prompt. Analytics from services such as Bubblemaps and various media reports suggest that on‑chain losses, while serious for impacted individuals, remained relatively limited in aggregate, with estimates around $23,000 and roughly a few dozen users affected, though some individuals publicly claimed much larger drains that have not all been corroborated on-chain. The case underscores an ongoing risk in crypto where attackers target Web2 infrastructure—domains, DNS, or team accounts—to push malicious prompts through otherwise trusted URLs, highlighting the need for both users and projects to harden domain security and verify any signature requests carefully before approval.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Crypto

Comments