Categories: Blockchain

Memecoin Launcher Pump.Fun Claims Ex-Employee Behind $1.9M Exploit

Solana memecoin creation tool pump.fun has claimed a former employee exploited the firm for nearly $2 million through a “bonding curve” attack. The ex-employee used their “privileged position” to access a “withdraw authority” and compromise the protocol’s internal systems, pump.fun alleged in a May 16 X post.

About $1.9 million was stolen from the total $45 million held in pump.fun’s bonding curve contracts. The platform temporarily paused trading but it is now back up and running. The pump.fun smart contracts “are safe,” and users impacted by the incident will receive “100% of the liquidity” that it previously had within the next 24 hours, pump.fun said.

Prior to pump.fun’s post, Igor Igamberdiev, the head of research at cryptocy market maker Wintermute, claimed the hack came about from an internal private key leak, which he suspected to be X user “STACCoverflow.”
In a series of cryptic X posts, STACCoverflow claimed they were “about to change the course of history. n [sic] then rot in jail.” They added in a separate post they “do not care, I am already fully doxxed.”
In an earlier X post, pump.fun said  it has been collaborating with law enforcement. It did not name the former employee and did not immediately respond to a request for comment.
The alleged exploiter used flash loans on a Solana lending protocol Raydium to borrow Solana’s SOL, token which was then used to “buy as many coins” as possible, pump.fun said.
Once the coins hit 100% on their respective bonding curves, the exploiter could then access the bonding curve liquidity and repay the flash loans.

Approximately 12,300 SOL, worth $1.9 million, was stolen in the attack, which pump.fun sai occurred between 3:21 pm and 5:00 pm UTC on May 16.

The Solana Memecoin Launchpad said users impacted between these hours would recover 100% or more of the liquidity held prior to the attack.

Terron Gold

Recent Posts

Candy Digital Announces Migration to Solana as NFT Platform Repositions for Long Term Growth

NFT platform Candy Digital has announced plans to migrate its digital collectibles ecosystem to the Solana blockchain, signaling…

7 hours ago

US Military Runs Bitcoin Node for National Security Testing, Admiral Tells Congress

The U.S. military has confirmed it is actively running a Bitcoin node as part of national security research, while…

7 hours ago

Over 90% of Web3 Games Failed After $15 Billion Boom as Players Never Showed Up

The Web3 gaming sector is facing a harsh reality check as new data reveals that more…

9 hours ago

Justin Sun Sues Trump Linked World Liberty Financial Over Frozen Crypto Assets

Justin Sun, founder of TRON, has filed a federal lawsuit against World Liberty Financial, a crypto venture…

11 hours ago

Tether Freezes $344 Million in USDT on Tron After Wallets Flagged by U.S. Authorities

Tether has frozen approximately $344 million in USDT on the Tron blockchain after the wallets were flagged by U.S. authorities, marking…

11 hours ago

Kalshi Fines and Suspends Three Congressional Candidates for Betting on Their Own Elections

Prediction market platform Kalshi has fined and suspended three U.S. congressional candidates after determining they engaged in “political…

12 hours ago