BONK.fun Domain Hijacked in Wallet Drainer Attack, Users Warned
BONK.fun, a cryptocurrency platform, faced a severe security breach on Thursday after attackers compromised its domain and deployed a wallet drainer. The exploit put users' funds at immediate risk, prompting urgent warnings from the team via social media.
The official BONK.fun X account confirmed the domain takeover, advising users to avoid interaction until security measures are restored. "A malicious actor has compromised the BONKfun domain—do not interact with the website until we have secured everything," the team posted.
Tom, a BONK.fun operator, revealed attackers hijacked a team account to inject the drainer. "Do not use the [BONK.fun] domain until further notice," he warned, emphasizing the urgency. The attack leveraged a fake Terms of Service prompt to target users, though existing wallet connections and external terminal traders remained unaffected.
The incident underscores lingering vulnerabilities in crypto frontends, even as decentralized protocols gain traction. Security remains a critical hurdle for mainstream adoption.