Bonk.fun, a popular Solana-based platform for launching new tokens, suffered a domain hijack attack. Hackers gained control of the website and injected a wallet-draining script that can empty victims' digital assets within seconds. Tom, the site's operator, issued an urgent warning urging users to stop using the platform immediately.
How the Attack Worked: A Fake Terms of Service Trap
The breach originated from a compromised staff account, giving attackers the ability to alter the website's front-end interface. They posted a fake "Terms of Service" update pop-up. Any user who clicked "Accept" inadvertently granted the hackers smart-contract permission to transfer all funds from their connected wallets. No further confirmation was needed—theft happened almost instantly.
This incident echoes the Aave $27 million liquidation event earlier this year, where a risk-management tool glitch caused safe loans to be closed. In both cases, internal or external failures of non-blockchain components led to financial damage. Bonk.fun's problem was not the blockchain itself but the website interface—a common attack vector as core protocols become harder to break.
Market Impact and User Risk
The BONK token's price currently stands at $0.00005943, reflecting a 4.65% decline over the past week. The blockchain and token contracts remain unaffected; only the Bonk.fun front-end was compromised.
Not every visitor is at risk. Only users who visited the site during the hijack and signed the fake message or approved the pop-up are vulnerable. Traders who used other apps or Telegram bots were not exposed.
Security experts note that domain hijacks with rented "scam kits" are becoming more common, making fake interfaces look indistinguishable from real ones. Users should avoid signing any unexpected prompts and move assets to a fresh wallet if they suspect exposure. Revoking old permissions and using hardware wallets remain the best defense.

