Crypto Warning: Bonk.fun Domain Hack Exposes Solana Traders To Wallet Drain

bitcoinistPublished on 2026-03-14Last updated on 2026-03-14

Abstract

Crypto platform Bonk.fun suffered a domain hijacking attack on March 12, 2026, exposing users to a wallet-draining exploit. Hackers injected a malicious script on the website, prompting users to sign a fake "Terms of Service" agreement, which, when approved, allowed the attackers to steal funds. The team confirmed that only users who interacted with the fraudulent prompt after the hack were affected, and losses were reported as minimal. The breach was attributed to a Web2 infrastructure failure rather than a smart contract exploit. This incident highlights the growing threat of approval-phishing and domain hijacking attacks in the crypto space, underscoring the need for heightened user caution and improved security practices.

A Crypto platform confirmed that their main domain website had been hacked, which exposed its users to a wallet draining exploit.

A No-Fun Crypto Hijack

It is a truth universally acknowledge that, no matter the size of a global geopolitical crisis, hackers will continue to ravage through the crypto market. This time, the victim was memecoin issuance platform Bonk.fun. In a March 12 post on the social network X, Tom (@SolportTom), one of its operators, warned the users not to interact with the domain “until further notice”, as hackers had injected a crypto wallet drainer on it:

The official X account of the Solana token launchpad, backed by Raydium and the BONK community, also announced the hack and echoed Tom’s striking warning:

Who Is Affected And How

Tom explained that the phishing scam set up a fake “Terms of Services” (TOS) signature prompt which, when signed, allowed the drainer to move the unaware user’s funds. According to Tom, the only users compromised were the ones who interacted with the fake TOS. He clarified that neither previously connected users nor traders of bonk fun tokens on third-party terminals were affected. He also assured that the security breach was spotted early so “the losses are minimal to date”:

This is not a Raydium or BONK smart contract exploit, but the case of a Web2 infrastructure failure that bled directly into Web3. This type of domain hijacking and phishing drainer scripts work by the attackers taking over the frontend and presenting normal-looking prompts that abuse wallet approvals.

A Pattern Of Exploited Vulnerabilities

In recent years, approval-phishing and “fake UI” attacks have stolen billions of dollars: one Chainalysis investigation reported the amount of $14 billion in on-chain scam inflows in 2025, with projections pointing above the $17 billion as more wallets continued to be identified.

As scam revenues grow and AI‐driven impersonation scales, crypto security in 2026 is less about the perfect code and more about defending everything around it: from domains to social accounts, employees and users decision-making. In February last year, attackers hijacked Pump.fun’s X account to push a fake PUMP token, as covered by our sister website NewsBTC. Not too long ago, OG trader Sillytuna was drove out of the crypto market after a multimillion-dollar theft that combined online address poisoning and offline violent actions.

The times are testing traders online and offline, both inside and outside the bloc. As the crypto landscape grows more complex, traders would do well to heighten their caution: prefer direct contract interaction or trusted aggregators, and use tools to monitor and regularly revoke token approvals.

SOL’s price trends to the upside on the daily chart. Source: SOLUSDT on Tradingview

Cover image from Perplexity, SOLUSDT chart from Tradingview

Related Questions

QWhat was the main security incident that occurred with Bonk.fun?

AThe main domain of Bonk.fun was hacked, and a wallet drainer was injected into the website, exposing users to a phishing scam.

QHow did the wallet drainer on Bonk.fun's compromised domain work?

AThe drainer set up a fake 'Terms of Services' (TOS) signature prompt. When users signed this prompt, it allowed the attacker to move their funds.

QAccording to the article, which users were affected by this security breach?

AOnly users who interacted with the fake TOS message on the compromised Bonk.fun domain after the hack were affected. Previously connected users and those trading on third-party terminals were not compromised.

QWhat type of exploit was this incident classified as, and what was its root cause?

AThis was not a smart contract exploit. It was a Web2 infrastructure failure (domain hijacking) that led to a Web3 phishing attack, where the frontend was compromised to present malicious prompts.

QWhat broader trend in crypto scams does the article mention, and what was a key statistic provided?

AThe article mentions that approval-phishing and 'fake UI' attacks have become a major trend. A Chainalysis investigation reported $14 billion in on-chain scam inflows in 2025, with projections exceeding $17 billion.

Related Reads

$9.4 Billion: The Largest Robotics Funding This Year Has Emerged

Munich-based humanoid robotics company Neura has completed a $1.4 billion (approximately RMB 94.9 billion) Series C funding round, valuing the company at around $7 billion and positioning it among the global leaders in the sector. The investment round is notable not just for its size—reportedly the largest in robotics this year—but also for its strategic backers, which include tech giants like NVIDIA and Amazon, alongside established industrial players such as German engineering firms Bosch and Schaeffler. This mix of investors signals a significant shift in the industry's focus from technological demonstrations and general-purpose narratives toward practical, industrial deployment and commercialization. Neura's approach centers on developing humanoid robots for defined, high-value industrial tasks rather than pursuing a general-purpose model. Its early validation comes from a partnership with BMW, where its robots are being tested on actual production lines. The involvement of Bosch and Schaeffler, companies deeply embedded in global manufacturing, underscores a growing belief that humanoid robots are transitioning from labs to viable factory-floor solutions. The article highlights two converging trends driving investment: advancements in AI and large language models, which enhance robots' perception and decision-making in unstructured environments, and mounting pressure from labor shortages and rising costs in major manufacturing regions. The funding landscape is now bifurcating between companies like Figure AI, focusing on versatile general-purpose robots, and firms like Neura, targeting specific vertical industrial applications with clearer, shorter paths to ROI. While technical hurdles remain, the core challenges for widespread adoption are increasingly seen as engineering and commercial in nature: managing the high integration and customization costs for different factory environments and establishing robust, localized maintenance and service networks. The record investment in Neura, particularly from industrial capital, indicates the industry's growing confidence in moving from proving feasibility to solving the practical problems of scalability, reliability, and building sustainable business models around humanoid robots in real-world settings like automotive manufacturing and hazardous labor environments.

marsbit2h ago

$9.4 Billion: The Largest Robotics Funding This Year Has Emerged

marsbit2h ago

"119 to 176 Dollars": Behind SpaceX's Listing, MSX Once Again Successfully Executes the Pre-IPO Closed Loop

Following May's 300% gain on Cerebras, MSX delivered another outstanding performance during SpaceX's listing night. On June 12, SpaceX (SPCX) launched on Nasdaq, reaching a high of $176. This marked the successful culmination of MSX's Pre-IPO project launched in March, where users subscribed at $119, achieving gains of approximately 40-48%. This event validated MSX's complete Pre-IPO mechanism, a crucial advantage in a market where access to top-tier private company equity is typically limited to institutions. MSX's model provides a full cycle for users: subscription (at $119 for SpaceX), real-time on-chain portfolio tracking, optional early redemption, seamless conversion to tradable spot assets (SPCX.M) upon IPO, and final settlement in stablecoins. This end-to-end process distinguishes MSX from platforms that faced settlement issues during the SpaceX IPO, highlighting that the core challenge of Pre-IPO is not just access, but a clear exit and conversion path post-listing. This success with SpaceX is MSX's second major Pre-IPO verification, following the Cerebras listing in May, which yielded ~300% returns for early participants. These back-to-back achievements demonstrate MSX's capability to source, structure, and deliver real assets through a replicable on-chain model. The true barrier for Pre-IPO products lies not in providing an entry point, but in ensuring reliable fulfillment from subscription through to post-IPO liquidity. MSX's proven闭环 (closed-loop) process addresses this, offering Web3 users a structured way to access high-growth, pre-public companies in sectors like AI and frontier tech. MSX plans to continue expanding its Pre-IPO portfolio with this focus on authenticity, transparency, and post-listing execution.

Odaily星球日报15h ago

"119 to 176 Dollars": Behind SpaceX's Listing, MSX Once Again Successfully Executes the Pre-IPO Closed Loop

Odaily星球日报15h ago

Trading

Spot
Futures
活动图片