Bonk.fun users at risk after hackers hijack domain to deploy wallet drainer

2026-3-12 10:51

Users of the Solana-based memecoin launchpad Bonk.fun were urged to avoid the platform’s website after attackers compromised its domain and deployed a malicious wallet-draining script designed to siphon funds from connected wallets.

The project confirmed the breach in a statement on social media, warning that the platform’s domain had fallen under the control of a malicious actor.

https://twitter.com/bonkfun/status/2031927971611922517?s=20

According to the team, the breach began when an attacker gained control of a team-associated account, which allowed the intruder to alter the website’s interface and inject a deceptive prompt that appeared as a standard terms-of-service confirmation. 

In reality, the prompt was linked to a wallet-draining program intended to trick visitors into signing a transaction that would grant the attacker permission to move assets from their wallets.

Tom, an operator associated with the project, also warned users that the hijacked account had been used to place the drainer directly on the domain.

“Do not use the bonk.fun domain until further notice, hackers have hijacked a team account forcing a drainer on the domain,” Tom wrote on X.

He clarified that the attack did not affect users who had previously interacted with the platform before the compromise.

“No if you connected to bonk fun in the past you’re not affected,” Tom said in a follow-up message, adding that traders accessing Bonk.fun tokens through third-party trading terminals were also unaffected.

Damages were limited

According to Tom, only visitors who signed the fake terms-of-service message during the window when the compromised interface was active were exposed to the wallet-draining script. 

The team said it quickly identified the incident and issued warnings across social media channels, which helped contain the damage.

Still, at least some users appear to have suffered losses. One trader claimed on X that they lost their entire wallet after connecting to the site.

“I just got drained for $273,000 on Bonk.fun,” the user wrote, saying their wallet was left “bone dry” after interacting with the compromised interface.

Bonk.fun has not disclosed the total value of funds affected so far.

“We’re doing everything in our power to fix the situation,” he said, noting that protecting the platform’s users remains the team’s main priority.

A persistent threat

Due to their popularity, token launchpads and other major crypto projects have repeatedly become targets for attackers.

A similar technique was used in a previous incident involving the decentralised finance protocol Curve Finance, where attackers hijacked the project’s domain name system and redirected users to a malicious clone designed to drain connected wallets.

Pump.fun, a rival Solana-based memecoin launchpad competing with Bonk.fun, was targeted last year after attackers hijacked its X account to promote fraudulent meme tokens.

The post Bonk.fun users at risk after hackers hijack domain to deploy wallet drainer appeared first on Invezz

origin »

Bitcoin price in Telegram @btc_price_every_hour

Bonk (BONK) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 3m BONK / 3m BONK

domain wallet users fun bonk fake used

domain wallet → Результатов: 47


Monero’s Cake Wallet now supports Unstoppable Domains’ .crypto usernames

Blockchain-based domain name provider Unstoppable Domains has announced support for Cake Wallet, a non-custodial, open-source Monero, Bitcoin, and Litecoin wallet. Now, Cake Wallet’s 150,000 users can send Monero (XMR), Bitcoin (BTC), and Litecoin (LTC) across 50+ wallets and exchanges with Unstoppable Domains’ easily readable usernames.

2021-8-13 19:18


Unstoppable Domains Announces Second Wave of Money and Manpower to Exchanges, Wallets and Browsers that Integrate .zil Domains

SAN FRANCISCO — 9. 12. 19 — Unstoppable Domains, a software company building domains on blockchains, today introduced its second installment of The Blockchain Domain Grant Program. For the latest round of grants, the Unstoppable Domains community selected Coinomi, the longest standing multi-asset wallet, CoinRequest, an adoption focused wallet simplifying day-to-day transactions, and Viewblock, a blockchain domain explorer.

2019-9-13 18:58


Фото:

Lazarus Hacker Group Continues to Target Crypto Using Faked Trading Software

This article was originally published by 8btc and written by Lylian Tang. The Chinese security service provider 360 Security has issued a warning that a large number of crypto exchanges have been targeted by the North Korean hacker group Lazarus and that the number is still rising after the recent hacks of crypto exchanges DragonEx, Etbox and BiKi.

2019-4-2 21:54


NEO Name Service Goes Live—Bidding Starts Today

The NEO Name Service (NNS) has gone live as of Tuesday, October 9th. Users are now able to bid on domain names ending in .neo. These names can be used to create custom wallet addresses, email addresses, smart contract hashes, and much more: The current bidding process is described as “mining”: users who successfully bid… The post NEO Name Service Goes Live—Bidding Starts Today appeared first on UNHASHED.

2018-10-10 01:51


Фото:

Blockchain.com Accuses Blockchain.io of Misleading Customers by Using Similar Domain Name, Logo, Site Colors, Tagline

They say imitation is the sincerest form of flattery, but for the crypto wallet provider Blockchain, with the blockchain. com domain, copying its business name is not a flattering matter at all. The company just lodged a complaint in a US court against another website accusing it of attempted deception and trying to mislead customers into […] Blockchain.

2018-9-27 15:49