Bonk.fun compromised: Domain taken over, cryptocurrency extractor installed.

29

The individual identified as Tom stated that only those users who accepted a fraudulent terms-of-service message on the compromised website post-breach were impacted.

Bonk.fun's domain compromised. (Clint Patterson/Unsplash)

What to know:

  • Bonk.fun, a community-centered Solana token issuance platform supported by Raydium and the BONK, alerted users to refrain from accessing its website after hackers took control of a team account and deployed a crypto drainer on the domain.
  • The operator, referred to as Tom, indicated that only individuals who accepted a fraudulent terms-of-service prompt on the compromised site after the breach were impacted.
  • Tom mentioned that the breach was identified rapidly, with losses not yet specified.

The one constant in the crypto landscape, regardless of market conditions, is the occurrence of hacks. On Thursday, hackers seized Bonk.fun’s domain, the Solana token launchpad backed by Raydium and BONK, and installed a wallet drainer.

Operator Tom communicated the breach to the community via his X account @SolportTom. “Do not visit the http://bonk.fun domain until further notice, hackers have compromised a team account and have deployed a drainer on the DOMAIN,” he stated. Bonk’s official X account corroborated this information.

The breach highlights ongoing vulnerabilities in crypto frontends, even as institutional interest surges and ecosystems expand.

Phishing attacks of this nature, which deceive users into accepting malicious prompts on compromised domains, have been a persistent issue within crypto. In 2025, these types of scams reached unprecedented levels, with fraudulent inflows nearing $17 billion amidst a 1,400% increase in AI-driven impersonations and “pig butchering” schemes.

The damage from the Bonk.fun breach is reportedly minimal at this time. Tom stated that previous connections to bonk.fun remain secure, as do trades conducted through third-party platforms. Only users who accepted a fraudulent terms-of-service prompt on the compromised site after the breach were affected, and prompt community notifications seem to have mitigated the impact.

“We are taking every measure to rectify the situation,” the operator stated, emphasizing a commitment to users who have relied on the platform for the last eight months. The operator did not disclose the specific amount of financial losses but highlighted that the incident was addressed swiftly.

BONK's X.