Bonk.fun’s Website Hijacked: Users Who Clicked Lost Everything in Their Wallets

0 440

Bonk.fun, the Solana-based memecoin launchpad formerly known as LetsBonk.fun and backed by the BONK community and decentralized exchange Raydium, had its domain compromised on Wednesday when attackers gained control of a team-associated account.

The access allowed them to alter the site’s frontend, the user-facing interface, and inject a prompt disguised as a routine terms-of-service confirmation.

Signing it authorised a wallet-draining contract, a malicious program that, once approved, empties a connected crypto wallet within seconds, to move assets out of any connected wallet immediately. 

The platform confirmed the breach on X: “A malicious actor has compromised the BONKfun domain, do not interact with the website until we have secured everything.”

The operator behind BONK Tom (SolportTom) elaborated: hackers had hijacked a team account and used it to force the drainer onto the live domain.

He was specific about who was at risk: only users who signed the fraudulent terms-of-service prompt during the active window of the compromise. Past connections to the site were safe; trades through external terminals were safe.

Browser security systems later flagged the domain for suspected phishing, and Decrypt confirmed visitors were met with security warnings. As of early Thursday, the team had not disclosed a timeline for declaring the domain safe or confirmed  Meanwhile, the total value drained was quite substantial. One user publicly claimed a loss of $273,000.

How a Frontend Attack Works

The Bonk.fun incident is a frontend attack, a class of exploit that targets the website layer sitting in front of a blockchain protocol rather than the smart contracts running beneath it. The underlying blockchain infrastructure was never compromised; every token and contract deployed through Bonk.fun remained intact. 

What the attacker controlled was the webpage itself. By injecting a malicious signing prompt, they turned a routine user action into an authorization for the drainer to empty connected wallets.

Users who accessed Bonk.fun tokens through third-party terminals were unaffected because those terminals pull data from the blockchain directly, bypassing the compromised website entirely.

This attack method is not new.. In 2022, decentralized exchange Curve Finance had its DNS, Domain Name System, the infrastructure that maps a web address to a server, hijacked and redirected users to a malicious clone. Aerodrome Finance was hit by a comparable front-end hijack in November 2025. 

These attacks are effective because they exploit trust in familiar interfaces rather than flaws in the underlying protocol. A user who verifies every transaction prompt before signing would likely catch the discrepancy. Most do not.

Context: A Platform Under Pressure

The timing compounds a difficult stretch for Bonk.fun. Launched in April 2025, the platform initially captured an estimation of roughly over 70% of Solana’s memecoin launchpad market, rapidly displacing rival Pump.fun. That dominance faded: by the end of 2025 its share had declined to approximately 7% as reward structures became harder to access. 

The platform cut fees to 0% in early 2026 to win back users, with limited effect, revenue reportedly fell to around $84,000 against Pump.fun’s $720,000 in a comparable period.

Chainalysis put total crypto phishing and scam losses at approximately $17 billion in 2025, driven in part by industrialised wallet-draining operations. The Bonk.fun incident is one of the first significant front-end attacks of 2026.

Leave A Reply

Your email address will not be published.