The post Hacker Drains $23K From Bonkfun Users After Fake Terms Message Exploit On Solana appeared on BitcoinEthereumNews.com. The Solana ecosystem faced anotherThe post Hacker Drains $23K From Bonkfun Users After Fake Terms Message Exploit On Solana appeared on BitcoinEthereumNews.com. The Solana ecosystem faced another

Hacker Drains $23K From Bonkfun Users After Fake Terms Message Exploit On Solana

For feedback or concerns regarding this content, please contact us at [email protected]

The Solana ecosystem faced another security scare after a hacker briefly took control of the website of the meme launch platform Bonkfun, tricking users into approving a malicious message that allowed attackers to drain funds from their wallets.

Early blockchain analysis suggests that at least 35 users have been affected, with roughly $23,000 stolen so far.

Blockchain analytics platform Bubblemaps first highlighted the scope of the exploit, noting that while some social media users claim much larger losses, the verifiable on-chain data currently points to a smaller figure.

The incident underscores a growing problem in crypto: social engineering attacks disguised as legitimate wallet approvals. Rather than exploiting the blockchain itself, attackers manipulate users into signing messages that give them access to funds.

Bonkfun Website Compromise Triggers Wallet Draining Incident

The exploit began earlier today when the official Bonkfun website was compromised by a hacker. According to the platform, the attacker modified the site in a way that prompted visitors to sign a fake terms-of-service message.

Users who interacted with the compromised interface were unknowingly granting permissions that allowed the attacker to drain funds from their wallets.

Bonkfun confirmed the breach publicly in a statement posted on X (formerly Twitter), explaining that the attacker temporarily gained control of the site infrastructure and injected malicious prompts.

The platform clarified that not all users were affected. Only individuals who visited the compromised website and signed the fake message after the breach occurred had their wallets exposed.

That distinction is important. Simply visiting the site did not trigger the exploit. The wallet-draining activity only occurred when users approved the fraudulent signature request presented as a standard agreement.

Security experts frequently warn that signing arbitrary messages can be dangerous because these approvals may grant hidden permissions to external contracts or scripts.

Bubblemaps Analysis Identifies Attacker Wallet Network

Shortly after the exploit surfaced, blockchain analytics firm Bubblemaps began tracing the funds. Using public blockchain data, the firm identified 13 wallet addresses linked to the attacker.

According to the investigation, those addresses collectively carried out the exploit operations and received the stolen funds.

In a statement shared on X, Bubblemaps reported that the attacker had already extracted funds from dozens of users.

The analytics firm summarized its findings:

  •  35 users exploited so far
  •  $23,000 in total funds drained
  •  13 addresses linked to the attacker

These figures are based on verified on-chain data combined with reports submitted by affected users.

Blockchain analysis tools make it possible to trace fund movements across addresses. While attackers can move assets between wallets, the public nature of most blockchains allows investigators to map relationships between addresses and identify patterns.

In this case, Bubblemaps said the attacker appears to be distributing stolen funds across several addresses tied to the same entity.

Claims Of Larger Losses Lack On-Chain Evidence

While the confirmed losses currently sit at around $23,000, several social media posts claim that individual users lost far larger sums—some even suggesting damages exceeding $100,000.

However, Bubblemaps says those claims have not been supported by blockchain evidence so far.

The firm explained that it reviewed wallet activity connected to the exploit and did not find transactions that would indicate six-figure losses. The investigation also involved attempts to contact individuals who claimed to be victims.

According to Bubblemaps, several alleged victims were contacted directly, but none responded with verifiable proof of larger losses.

That doesn’t necessarily mean the claims are false, but at this stage investigators say the blockchain data simply does not support the higher estimates circulating online.

In crypto incidents, misinformation often spreads quickly, especially in communities built around high-volatility assets like meme coins. Analysts usually rely on on-chain evidence rather than anecdotal reports when estimating the scale of an exploit.

Social Engineering Attacks Continue To Target Crypto Users

The Bonkfun exploit highlights a tactic that has become increasingly common across the crypto industry: wallet-draining scams that rely on user approvals rather than smart-contract vulnerabilities.

Instead of hacking the blockchain or breaking cryptographic security, attackers design malicious interfaces that trick users into signing approvals they don’t fully understand.

These approvals can allow the attacker to:

  •  Transfer tokens from the victim’s wallet
  •  Execute transactions on their behalf
  •  Interact with contracts using their wallet permissions

The fake terms-of-service prompt used in the Bonkfun exploit is a typical example of this strategy. Because signing messages is common in decentralized applications, many users approve requests quickly without reviewing the details.

Security researchers often recommend that users carefully check any wallet prompt before approving it—especially if the request appears unexpectedly.

Many modern wallet tools now include transaction simulation features that display exactly what will happen if a message is signed. However, not all users take advantage of these safeguards.

Investigation Continues As Analysts Monitor Attacker Wallets

The situation is still developing, and investigators say they will continue monitoring the wallets associated with the exploit.

Because blockchain transactions are public, analysts can track whether the attacker attempts to move the funds through exchanges, bridges, or mixing services.

If the stolen assets eventually interact with centralized exchanges, it may be possible for platforms to flag or freeze the funds, depending on compliance policies.

For now, Bubblemaps says it will continue tracking the 13 identified addresses connected to the attacker and update the community if new activity appears.

Meanwhile, Bonkfun has regained control of its website and is working to ensure the platform remains secure. The team also urged users to remain cautious and verify any wallet requests before signing them.

The incident serves as another reminder that in crypto, the biggest risks often come from interface manipulation rather than protocol-level vulnerabilities.

As decentralized platforms grow more popular—especially meme-driven ecosystems on networks like Solana—security experts warn that attackers will likely continue targeting users through similar social-engineering tactics.

For now, the confirmed damage appears relatively limited compared with other recent exploits. But even a $23,000 incident shows how quickly funds can disappear when users unknowingly approve malicious transactions.

And with blockchain investigators still watching the attacker’s wallets, the final chapter of the Bonkfun exploit may not be written just yet.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.

Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news!

Source: https://nulltx.com/hacker-drains-23k-from-bonkfun-users-after-fake-terms-message-exploit-on-solana/

Market Opportunity
Notcoin Logo
Notcoin Price(NOT)
$0.0003855
$0.0003855$0.0003855
+0.15%
USD
Notcoin (NOT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ripple’s XRP Millionaires are Back in Business as Market Pundits Cite Expected Price Target ⋆ ZyCrypto

Ripple’s XRP Millionaires are Back in Business as Market Pundits Cite Expected Price Target ⋆ ZyCrypto

The post Ripple’s XRP Millionaires are Back in Business as Market Pundits Cite Expected Price Target ⋆ ZyCrypto appeared on BitcoinEthereumNews.com. Advertisement
Share
BitcoinEthereumNews2026/03/14 22:41
Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Daily market key data review and trend analysis, produced by PANews.
Share
PANews2025/04/30 13:50
Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36