Bonk.fun Hack Exposes Solana Users to Wallet Drainer Attack

TheNewsCryptoPublished on 2026-03-12Last updated on 2026-03-12

Abstract

A security vulnerability on the Bonk.fun platform exposed Solana users to wallet drainer attacks. Malicious scripts were injected into the site, redirecting users to phishing pages that prompted them to approve transactions. These approvals allowed attackers to automatically drain tokens from users' wallets. The platform, which is used for meme token trading, was compromised, and users were deceived through fake reward claims and interface changes. Bonk.fun issued a warning on X, advising users not to interact with the site until it was secured. The developer team acted quickly to remove the malicious scripts and urged users to revoke any suspicious approvals. The incident raised concerns in the crypto community, though the prompt response helped mitigate potential damage.

The security vulnerability on Bonk.fun allowed malicious wallet drainer links to affect users who were not aware of the danger. Additionally, security experts detected the vulnerability after users encountered suspicious approval prompts while interacting with the Bonk.fun platform. The attacker injected malicious scripts to redirect users to phishing sites that demanded approvals from their connected wallets. These approvals allowed the malicious programs to drain the users’ tokens automatically from their wallets to the attacker’s addresses.

The exploit raised several concerns in the Solana ecosystem. The Bonk.fun is a site that interacts with the trading of meme tokens and the Decentralized Finance community. The attackers tried to deceive users by mimicking reward claims and token distribution through malicious interface changes. After the users accepted the request, the drainer would drain the assets from the users’ wallets within a matter of seconds.

The official X post of Bonk.fun said, “A malicious actor has compromised the BONKfun domain. Do not interact with the website until we have secured everything.”

Platform Response and Community Warnings

The developer community reacted quickly after the news became public. And immediately removed the malicious scripts that affected the Bonk.fun interface. The developer team immediately reviewed all integrations and external scripts associated with the interface that attackers might have exploited. The platform operators immediately alerted users to revoke any approvals made by malicious tokens. And to avoid clicking on unknown links shared in crypto-related groups. Blockchain investigators are closely monitoring the attacker’s wallets and all transactions associated with the exploit campaign.

Tom, the operator of Bonk.fun explained the issue on his X post. He expressed his answers saying, “We understand a lot of people are scared and rightly so, but we’re doing everything in our power to fix the situation.”

The crypto market took the incident seriously, as security vulnerabilities are a major concern for investors and affect the overall market sentiment. Meanwhile, market sentiment toward new meme token markets remained cautious. However, analysts argued that the quick response from the developer community could help limit potential damage. The potential damage that might be caused by a security incident involving a decentralized interface. The users of the Bonk interface alerted each other through social media networks, warning them of the phishing approvals that are being made by malicious tokens associated with the interface.

Highlighted Crypto News:

Metaplanet Launches Venture Arm to Expand Bitcoin Ecosystem Amid Market Volatility

TagsBlockchainBONKsecuritySolanaSolana (SOL)

Related Questions

QWhat was the security vulnerability on Bonk.fun that affected Solana users?

AThe security vulnerability on Bonk.fun allowed malicious wallet drainer links to be injected, which redirected users to phishing sites. These sites then prompted users for approvals from their connected wallets, enabling malicious programs to automatically drain tokens from their wallets to the attacker's addresses.

QHow did the attackers deceive users on the Bonk.fun platform?

AThe attackers deceived users by mimicking reward claims and token distribution through malicious interface changes. After users accepted the approval requests, the drainer would drain the assets from their wallets within seconds.

QWhat was the official response from Bonk.fun regarding the domain compromise?

AThe official X post of Bonk.fun warned users, stating: 'A malicious actor has compromised the BONKfun domain. Do not interact with the website until we have secured everything.'

QWhat actions did the developer community take after the Bonk.fun exploit was discovered?

AThe developer community quickly removed the malicious scripts affecting the Bonk.fun interface, reviewed all integrations and external scripts for potential exploits, and alerted users to revoke any approvals made by malicious tokens and avoid clicking on unknown links.

QHow did the crypto market and community react to the Bonk.fun security incident?

AThe crypto market took the incident seriously as security vulnerabilities are a major concern for investors, affecting overall market sentiment. Users alerted each other through social media networks about phishing approvals, while analysts noted that the quick response from developers helped limit potential damage.

Related Reads

Expect news tomorrow: this time the Bank of Japan will announce its interest rate decision! What impact will this have on Bitcoin?

A day before the Bank of Japan's (BOJ) interest rate decision announcement, the Japanese yen surged nearly 3% against the US dollar. The sharp move in the currency market fueled speculation that the Japanese government may have intervened again to support the yen. The USD/JPY pair fell over 400 pips to 158.5, its steepest daily drop since Japan's currency intervention earlier this year. Market participants suspect the rapid, strong yen appreciation could be due to direct foreign currency sales by Japanese authorities, though the Ministry of Finance has made no official statement. The yen had previously fallen to its weakest level against the dollar in nearly 40 years. In late April and May, the government intervened with roughly 9.6 trillion yen to prevent the USD/JPY from rising sustainably above 160, but the yen faced renewed selling pressure afterward. Investors are now focused on the BOJ's rate decision and its signals on future monetary policy. Potential hawkish signals from the BOJ are seen as a factor that could support further yen strength. A sharp yen appreciation could create short-term selling pressure on Bitcoin by increasing the risk of unwinding carry trades, where investors borrow low-yielding yen to invest in Bitcoin and other risky assets. This pressure could intensify if the BOJ takes a hawkish stance or raises interest rates.

cryptonews.ru23m ago

Expect news tomorrow: this time the Bank of Japan will announce its interest rate decision! What impact will this have on Bitcoin?

cryptonews.ru23m ago

Bernstein Reveals Details of Core Scientific's $14 Billion Deal with AMD

Analysts from Bernstein revealed details of a deal between Core Scientific and AMD with a potential total value of over $14 billion. According to the report, initial contracts for 530 MW of capacity could generate this revenue over 15 years, with AMD acting as a credit guarantor for part of the bitcoin miner's infrastructure. The partnership, announced on July 28, has the potential to allocate up to 2.5 GW of data center capacity for AI. Bernstein broke down the 530 MW into 377 MW of direct triple-net lease for AMD and 152 MW for an unnamed cloud provider backed by AMD's credit. This structure is seen as lowering financing costs and counterparty risk. AMD also received warrants to buy 30 million Core Scientific shares at $23.47 each, which vest upon reaching the 2.5 GW target. Average annual revenue from the deal is estimated at around $0.9 billion, or about $1.8 million per megawatt, which is 5-25% below recent AI hosting deals by other miners. However, the 377 MW triple-net lease for AMD carries a margin close to 100%. Core Scientific expects capital expenditures for the deal to be $11-12 million per MW, totaling about $6 billion. Bernstein views this partnership as a new phase in the transformation of former bitcoin miners into AI infrastructure operators, with AI chipmakers like AMD now acting as direct anchor tenants. Recent similar deals include Hut 8 allocating 704 MW to a tenant believed to be Nvidia, and AMD reserving 200 MW with Riot Platforms. Core Scientific also paid Block $41.9 million to terminate a mining chip supply contract as part of its accelerated diversification into AI.

cryptonews.ru1h ago

Bernstein Reveals Details of Core Scientific's $14 Billion Deal with AMD

cryptonews.ru1h ago

Trading

Spot
活动图片