Categories: Blockchain

Memecoin Launcher Pump.Fun Claims Ex-Employee Behind $1.9M Exploit

Solana memecoin creation tool pump.fun has claimed a former employee exploited the firm for nearly $2 million through a “bonding curve” attack. The ex-employee used their “privileged position” to access a “withdraw authority” and compromise the protocol’s internal systems, pump.fun alleged in a May 16 X post.

About $1.9 million was stolen from the total $45 million held in pump.fun’s bonding curve contracts. The platform temporarily paused trading but it is now back up and running. The pump.fun smart contracts “are safe,” and users impacted by the incident will receive “100% of the liquidity” that it previously had within the next 24 hours, pump.fun said.

Prior to pump.fun’s post, Igor Igamberdiev, the head of research at cryptocy market maker Wintermute, claimed the hack came about from an internal private key leak, which he suspected to be X user “STACCoverflow.”
In a series of cryptic X posts, STACCoverflow claimed they were “about to change the course of history. n [sic] then rot in jail.” They added in a separate post they “do not care, I am already fully doxxed.”
In an earlier X post, pump.fun said  it has been collaborating with law enforcement. It did not name the former employee and did not immediately respond to a request for comment.
The alleged exploiter used flash loans on a Solana lending protocol Raydium to borrow Solana’s SOL, token which was then used to “buy as many coins” as possible, pump.fun said.
Once the coins hit 100% on their respective bonding curves, the exploiter could then access the bonding curve liquidity and repay the flash loans.

Approximately 12,300 SOL, worth $1.9 million, was stolen in the attack, which pump.fun sai occurred between 3:21 pm and 5:00 pm UTC on May 16.

The Solana Memecoin Launchpad said users impacted between these hours would recover 100% or more of the liquidity held prior to the attack.

Terron Gold

Recent Posts

ZachXBT Raises Liquidity Concerns Over AscendEX as Users Report Weeks-Long Withdrawal Delays

On-chain investigator ZachXBT has publicly questioned the financial health of cryptocy exchange AscendEXafter mounting reports of users waiting days—and…

2 days ago

Tether Puts $23 Billion Gold Reserve to Work With New Bitcoin-Style Lending Program

Tether is expanding beyond stablecoins once again—this time by turning its massive $23 billion gold reserve into an…

2 days ago

Michael Saylor Calls Bitcoin Slump a ‘Volatility Test’ as Strategy’s Preferred Stock Hits Record Low

Strategy Executive Chairman Michael Saylor is standing by his long-term Bitcoin strategy despite mounting pressure from investors as…

3 days ago

Polymarket to Fully Refund Users After $2.9 Million Phishing Attack Exposes Third-Party Security Weakness

Polymarket has pledged to fully reimburse users after hackers stole approximately $2.9 million through a sophisticated phishing attack…

3 days ago

Coinbase’s Base Network Recovers After Two-Hour Outage Ahead of Major Blockchain Upgrade

Base, the Ethereum Layer-2 blockchain incubated by Coinbase, has fully restored operations after suffering a block production…

4 days ago

Bitcoin Falls Below $60,000 as Crypto Heads for Rare Back-to-Back Quarterly Losses

Bitcoin has fallen below the $60,000 level once again, placing the world's largest cryptocy on pace to record…

4 days ago