BONK.fun relaunches after domain hijack, confirms $30K in losses

ambcryptoPublicado em 2026-03-20Última atualização em 2026-03-20

Resumo

BONK.fun has restored its website following a domain hijack incident that resulted in approximately $30,000 in user losses. The breach, caused by a social engineering attack targeting its domain service provider, led to an unauthorized domain transfer. The attackers did not compromise BONK.fun’s internal systems or codebase. A phishing interface was deployed, tricking users into signing malicious transactions. The team will reimburse affected users at 110% of their losses. Full functionality was restored by March 19, though some antivirus providers still flag the domain. BONK’s price remains weak, trading near $0.0000059. The incident underscores vulnerabilities in third-party infrastructure rather than protocol-level flaws.

BONK.fun has restored its website following last week’s domain hijack. They confirm that the incident stemmed from a third-party provider breach and resulted in approximately $30,000 in user losses.

In an update shared on 20 March, the team said the attack was caused by a social engineering exploit targeting its domain service provider, which led to the domain being transferred to an external registrar.

The provider has since accepted responsibility for the incident.

The team added that there was no compromise of BONK. fun’s internal systems, codebase, or team accounts. They framed the attack as an external infrastructure breach rather than a protocol-level failure.

BONK phishing attack traced to domain takeover

The breach allowed attackers to take control of the BONK.fun website and deploy a phishing interface that prompted users to sign malicious transactions.

Earlier reports linked the attack to a fake terms-of-service signature request, which enabled unauthorized wallet access.

Blockchain analytics platform Bubblemaps had initially estimated losses at around $23,000, but the BONK.fun team has now revised that figure to $30,000.

In response, the team said it will reimburse affected users at 110% of their losses, covering both direct losses and opportunity costs.

Recovery delayed by registrar transfer

BONK.fun said the unauthorized domain transfer significantly slowed its ability to respond, as the domain was temporarily beyond its reach.

The domain was eventually restored on 18 March, with full functionality — including wallet integrations — returning by 19 March.

Wallet providers, including Phantom, MetaMask, and Solflare, were among those that helped flag the compromised domain.

Site relaunches, but warnings remain

Although BONK.fun is now back online, the team noted that some antivirus providers still flag its primary domain.

As a workaround, users experiencing access issues have been directed to an alternative domain, which mirrors the platform’s functionality.

BONK price shows continued weakness

Market reaction to the incident has remained muted, with BONK’s price continuing a broader downtrend.

At the time of writing, the token was trading near $0.0000059, reflecting ongoing weakness since early March highs.

Source: TradingView

The chart shows limited recovery momentum following the exploit, suggesting that sentiment remains cautious despite the platform’s relaunch.


Final Summary

BONK.fun has relaunched after a domain-level breach, confirming $30K in losses and offering full reimbursement to affected users.

The incident highlights how third-party infrastructure, not smart contracts, remains a key vulnerability in crypto platforms.


Perguntas relacionadas

QWhat was the cause of the BONK.fun domain hijack and how much were the user losses?

AThe domain hijack was caused by a social engineering exploit targeting BONK.fun's domain service provider, which led to the domain being transferred to an external registrar. The incident resulted in approximately $30,000 in user losses.

QDid the attack compromise any of BONK.fun's internal systems or codebase?

ANo, the team confirmed there was no compromise of BONK.fun's internal systems, codebase, or team accounts. They framed the attack as an external infrastructure breach.

QHow did the attackers exploit the hijacked domain, and what was the initial loss estimate?

AThe attackers deployed a phishing interface on the hijacked website that prompted users to sign malicious transactions. Blockchain analytics platform Bubblemaps initially estimated losses at around $23,000, which was later revised to $30,000 by the BONK.fun team.

QWhat compensation is BONK.fun providing to affected users and why was the recovery delayed?

ABONK.fun will reimburse affected users at 110% of their losses, covering both direct losses and opportunity costs. The recovery was delayed because the unauthorized domain transfer temporarily put the domain beyond the team's reach, slowing their response.

QWhat is the current status of the BONK.fun website and the BONK token's market performance?

AThe BONK.fun website has been restored with full functionality, though some antivirus providers still flag the primary domain, leading the team to provide an alternative domain for access. The BONK token continues to show weakness, trading near $0.0000059 with limited recovery momentum.

Leituras Relacionadas

Agent Race Ends, Super Workbench Takes Over

The era of fragmented AI agents is ending. Over the past month, China's tech giants—Tencent, Alibaba, and ByteDance—have simultaneously shifted strategy: instead of launching new, standalone AI agents, they are consolidating their various agent projects into unified "super workbenches." Tencent integrated its QClaw teams into WorkBuddy, a strategic product hailed as a potential third flagship after QQ and WeChat. Alibaba is merging its QoderWork, Wukong, and MuleRun agents into a new "Qianwen Office" platform under DingTalk's leadership. ByteDance rebranded its TRAE SOLO coding agent to TRAE Work, signaling a broader focus on workflow collaboration. This convergence marks a pivotal industry consensus. The initial exploration phase, where companies rapidly built numerous overlapping agents for different scenarios, proved costly and inefficient. With open-source tools eroding technical barriers, competition has shifted from agent creation to resource consolidation and cost control. Historically, platform wars are won not by creating more products, but by simplifying them—as seen with browsers unifying web access and super-apps consolidating services. Now, the "super workbench" aims to become the unified AI entry point for work. This reflects a deeper market realization: the primary audience for AI is no longer just programmers (a market in the tens of millions) but all knowledge workers (a market of billions). The real opportunity lies in augmenting everyday tasks—managing emails, documents, data, and meetings—across the entire workday. The core battleground is becoming control over the primary AI entry point that employees use daily. Tencent's WorkBuddy leverages WeChat and Tencent Docs; Alibaba's Qianwen Office taps into DingTalk's organizational data; ByteDance's TRAE Work integrates with Feishu's workflows. Whoever owns this "super workbench" gains strategic control over orchestrating enterprise data and APIs. This shift is redefining enterprise software. Traditional SaaS applications, valued for their user interfaces, will recede into the background. Their core functionalities will be exposed as standardized "Skills" or APIs for the super workbench's agents to invoke. Software value will shift from selling user seats to charging based on API calls and outcomes delivered. The evolution of agents is moving through clear stages: first as novel standalone products, then as consolidated primary work entry points, and finally as pervasive, invisible capabilities embedded into the digital fabric. The recent moves by major tech firms signal the transition from the first stage into the second, accelerating toward the third. In the end, the most successful agent technology may become invisible—like electricity or the HTTP protocol—a fundamental, unnamed infrastructure powering work itself.

marsbitHá 8m

Agent Race Ends, Super Workbench Takes Over

marsbitHá 8m

Michael Saylor: 110 Reasons to Oppose BIP-110

Michael Saylor presents 110 arguments against Bitcoin Improvement Proposal (BIP) 110, a soft fork aimed at restricting certain non-monetary data storage uses (like inscriptions) on the Bitcoin blockchain. He acknowledges the proponents' valid concerns—such as node costs, fee pressure, and preserving Bitcoin's monetary focus—but fundamentally disagrees with the proposed solution. Saylor argues that BIP 110 represents a dangerous precedent of using consensus rules to enforce value judgments on transaction validity, moving away from Bitcoin's core principles of neutrality and permissionless innovation. His key objections are organized into eleven categories: 1) It violates neutrality and hard consensus by banning currently valid transactions. 2) It fails to meet the high burden of proof required for a consensus change, lacking concrete data on the alleged crisis. 3) Its seven bundled technical restrictions are overly broad, targeting generic script functionalities and blocking future upgrade paths. 4) It sacrifices compatibility and future optionality by closing off designed upgrade hooks. 5) Its temporary rules add significant complexity (grandfathering, expiry states) without sufficient justification. 6) The economic and security impacts, particularly on miner revenue and fee markets, are uncertain and unmodeled. 7) Superior, market-based tools (fee markets, relay/mining policies) already exist to manage blockchain load. 8) It stifles innovation by creating a chilling effect for developers. 9) Its modified activation mechanism (55% threshold, forced signaling) is aggressive and risks network splits. 10) The precedent it sets—using consensus to suppress disliked but legal uses—is more dangerous than the problem it aims to solve. 11) A better path exists: improving measurements, refining resource-based policies, and allowing market forces to work. Saylor concludes that Bitcoin's strength lies in its neutral rules, open markets, and hard consensus. Changing these foundational elements to target specific use cases is an unnecessary and risky "iatrogenic" intervention. He advocates for guarding Bitcoin's neutrality rather than acting as its redeemer.

marsbitHá 23m

Michael Saylor: 110 Reasons to Oppose BIP-110

marsbitHá 23m

Trading

Spot
活动图片