The official website of Bonk.fun, a Solana-based memecoin launchpad, was hijacked early Wednesday in an attack that saw malicious actors inject a fake terms-of-service prompt into the site. Users who accepted the prompt unknowingly triggered a wallet-draining script that transferred digital assets out of their connected wallets.
Fake Terms Page Triggered Wallet-Draining Mechanism
According to Tom (X handle: @SolportTom), the operator behind Bonk, attackers compromised a team account and used that access to place the malicious drainer directly on the platform's domain. The fake terms page looked legitimate to visitors, creating a trap where anyone who clicked 'agree' signed a transaction that handed control of their funds to the attackers.
Tom clarified that only those who interacted with the fraudulent pop-up during the brief window of compromise suffered losses. The team detected the breach soon after it began and took immediate action to secure the domain and remove the malicious script. Engineers restored full control of the site, and Tom reassured the community that infrastructure monitoring remains tight to prevent further damage.
Rapid Response Contained the Damage
Bonk.fun (formerly LetsBonk.fun) has grown rapidly within the Solana ecosystem by offering instant token creation and automated liquidity via bonding curves. Part of its platform fees are directed to BONK buybacks and burns. The breach did not impact the underlying blockchain but highlighted how domain-level exploits can bypass even secure smart contracts.
Phishing Attacks Escalate Across Crypto
Blockchain analytics firm Chainalysis estimates that total crypto scam losses reached approximately $17 billion in 2025, as fraud operations become more organized and industrialized. Domain hijacking combined with deceptive prompts represents a growing attack vector: rather than breaking blockchain security, hackers prey on user trust in familiar interfaces.
The Bonk team continues monitoring the platform closely and reminds users to verify domain URLs and pop-up content before signing any transaction.

