Crypto Warning: Bonk.fun Domain Hack Exposes Solana Traders To Wallet Drain

bitcoinistPubblicato 2026-03-14Pubblicato ultima volta 2026-03-14

Introduzione

Crypto platform Bonk.fun suffered a domain hijacking attack on March 12, 2026, exposing users to a wallet-draining exploit. Hackers injected a malicious script on the website, prompting users to sign a fake "Terms of Service" agreement, which, when approved, allowed the attackers to steal funds. The team confirmed that only users who interacted with the fraudulent prompt after the hack were affected, and losses were reported as minimal. The breach was attributed to a Web2 infrastructure failure rather than a smart contract exploit. This incident highlights the growing threat of approval-phishing and domain hijacking attacks in the crypto space, underscoring the need for heightened user caution and improved security practices.

A Crypto platform confirmed that their main domain website had been hacked, which exposed its users to a wallet draining exploit.

A No-Fun Crypto Hijack

It is a truth universally acknowledge that, no matter the size of a global geopolitical crisis, hackers will continue to ravage through the crypto market. This time, the victim was memecoin issuance platform Bonk.fun. In a March 12 post on the social network X, Tom (@SolportTom), one of its operators, warned the users not to interact with the domain “until further notice”, as hackers had injected a crypto wallet drainer on it:

The official X account of the Solana token launchpad, backed by Raydium and the BONK community, also announced the hack and echoed Tom’s striking warning:

Who Is Affected And How

Tom explained that the phishing scam set up a fake “Terms of Services” (TOS) signature prompt which, when signed, allowed the drainer to move the unaware user’s funds. According to Tom, the only users compromised were the ones who interacted with the fake TOS. He clarified that neither previously connected users nor traders of bonk fun tokens on third-party terminals were affected. He also assured that the security breach was spotted early so “the losses are minimal to date”:

This is not a Raydium or BONK smart contract exploit, but the case of a Web2 infrastructure failure that bled directly into Web3. This type of domain hijacking and phishing drainer scripts work by the attackers taking over the frontend and presenting normal-looking prompts that abuse wallet approvals.

A Pattern Of Exploited Vulnerabilities

In recent years, approval-phishing and “fake UI” attacks have stolen billions of dollars: one Chainalysis investigation reported the amount of $14 billion in on-chain scam inflows in 2025, with projections pointing above the $17 billion as more wallets continued to be identified.

As scam revenues grow and AI‐driven impersonation scales, crypto security in 2026 is less about the perfect code and more about defending everything around it: from domains to social accounts, employees and users decision-making. In February last year, attackers hijacked Pump.fun’s X account to push a fake PUMP token, as covered by our sister website NewsBTC. Not too long ago, OG trader Sillytuna was drove out of the crypto market after a multimillion-dollar theft that combined online address poisoning and offline violent actions.

The times are testing traders online and offline, both inside and outside the bloc. As the crypto landscape grows more complex, traders would do well to heighten their caution: prefer direct contract interaction or trusted aggregators, and use tools to monitor and regularly revoke token approvals.

SOL’s price trends to the upside on the daily chart. Source: SOLUSDT on Tradingview

Cover image from Perplexity, SOLUSDT chart from Tradingview

Domande pertinenti

QWhat was the main security incident that occurred with Bonk.fun?

AThe main domain of Bonk.fun was hacked, and a wallet drainer was injected into the website, exposing users to a phishing scam.

QHow did the wallet drainer on Bonk.fun's compromised domain work?

AThe drainer set up a fake 'Terms of Services' (TOS) signature prompt. When users signed this prompt, it allowed the attacker to move their funds.

QAccording to the article, which users were affected by this security breach?

AOnly users who interacted with the fake TOS message on the compromised Bonk.fun domain after the hack were affected. Previously connected users and those trading on third-party terminals were not compromised.

QWhat type of exploit was this incident classified as, and what was its root cause?

AThis was not a smart contract exploit. It was a Web2 infrastructure failure (domain hijacking) that led to a Web3 phishing attack, where the frontend was compromised to present malicious prompts.

QWhat broader trend in crypto scams does the article mention, and what was a key statistic provided?

AThe article mentions that approval-phishing and 'fake UI' attacks have become a major trend. A Chainalysis investigation reported $14 billion in on-chain scam inflows in 2025, with projections exceeding $17 billion.

Letture associate

Microsoft is Afraid of Being Marginalized by AI Giants

Microsoft, once the defining force of the PC era, now faces a familiar challenge in the AI age: the risk of being relegated to a profitable but invisible infrastructure provider. This anxiety was laid bare at Build 2026, where CEO Satya Nadella unveiled a major strategic pivot. The catalyst was a quiet April agreement that dissolved Microsoft's exclusive licensing and cloud-hosting deal with OpenAI, its once-vital partner. This erased Microsoft's key AI moat. With OpenAI and Anthropic defining AI applications and gaining enterprise traction—even within Microsoft's own ranks—Nadella had to answer: without exclusivity, what is Microsoft's role? The answer was a suite of seven in-house AI models, a developer-focused AI workstation (Surface RTX Spark Dev Box), and, most crucially, the Agent 365 platform for enterprise AI governance. The models, notably targeting Anthropic's strengths in coding and enterprise, signal a defensive move. However, the broader strategy is to make the models themselves less decisive. Financially, Microsoft's AI revenue is strong, driven largely by Azure running others' models. Yet its user-facing products like Copilot show weak penetration and engagement. Microsoft earns infrastructure money but lacks direct user mindshare. Nadella's core fear is being "hollowed out." As OpenAI and Anthropic prepare for IPOs and gain financial independence, they may build their own infrastructure, threatening Azure's lucrative AI revenue stream. Microsoft's window is to entrench itself deeper: not as the model creator, but as the indispensable platform for securely deploying, managing, and governing all AI models within the enterprise through Agent 365. Build 2026 revealed Microsoft's bet: in the AI era, the ultimate power lies not in any single model, but in the enterprise "operating system" that controls them. Nadella is determined to ensure Microsoft is the driver of this new era, not just a passenger.

marsbit11 min fa

Microsoft is Afraid of Being Marginalized by AI Giants

marsbit11 min fa

CPU, Quietly Returning to the Center of the AI Computing Power Stage

Over the past three years, AI computing power narratives have been dominated by GPUs. However, starting in 2026, this story began to shift. While training large models remains GPU-intensive, the rapid growth of inference and AI agent workloads, which require high levels of task orchestration, concurrency, and data flow management, has highlighted a renewed critical role for CPUs. These are tasks GPUs are not designed to handle. Intel's recent launch of the Xeon 6+ processor, built on its Intel 18A process and featuring up to 288 efficiency cores (E-cores), exemplifies this strategic pivot. It is positioned not as a mere companion to GPUs but as the essential "control plane" for AI infrastructure, optimized for high-density, energy-efficient, and high-throughput workloads characteristic of AI agents and inference. This "CPU resurgence" is not about CPUs outperforming GPUs in raw computation. It reflects a systemic bottleneck: as AI scales from training single models to deploying countless intelligent agents, the demand for coordination and data handling surges. Major cloud providers are also developing their own high-density ARM-based server CPUs for similar workloads. However, Intel's success with this strategy faces significant challenges. Competition includes NVIDIA's integrated CPU-GPU solutions, the expanding adoption of cloud vendors' in-house ARM CPUs, and the crucial market test of Intel's 18A manufacturing process against rivals like TSMC's N2. In conclusion, CPUs are indeed reclaiming a central, though redefined, role in AI compute—managing the complex orchestration that enables massive-scale AI deployment. While the trend is clear, which company will ultimately lead this CPU resurgence remains an open question to be decided in the data centers of 2027 and beyond.

marsbit32 min fa

CPU, Quietly Returning to the Center of the AI Computing Power Stage

marsbit32 min fa

Trading

Spot
Futures
活动图片