The official website of Bonk.fun, a meme coin launchpad built on Solana, has been compromised in a security incident. Hackers hijacked the domain and injected malicious code designed to drain users' cryptocurrency wallets when they interact with the page.
Bonk.fun announced via its official X account: "A malicious attacker has taken over the BONKfun domain. Please do not interact with the website in any way until we have fully secured it."
The Trap: A Fake “Terms of Service” Prompt
Bonk operator Tom (@SolportTom) provided further details. The attackers gained control of the team's account and forcibly deployed a crypto drainer on the domain. Tom stated that only users who mistakenly signed a counterfeit "Terms of Service" prompt on the site would suffer asset losses. He emphasized that the operations team detected the breach almost immediately, so the actual financial damage was minimal.
No further updates have been released by Bonk.fun as of press time.
Crypto Scam Losses Hit $17 Billion in 2025
Driven by advances in AI and the proliferation of wallet-draining tools, phishing attacks in the crypto sector have become increasingly sophisticated. Hackers now favor domain hijacking, identity theft, and social engineering to directly exploit user trust. According to a Chainalysis report, global crypto scam losses reached a staggering $17 billion in 2025, with major scam operations becoming highly industrialized at an alarming pace.

