Overview
- Bonk.fun says a team account was compromised, letting attackers inject a wallet-draining prompt on the bonk.fun domain.
- Only users who signed the fraudulent terms-of-service message after the breach were exposed; prior connections and trades via third-party terminals were not affected.
- Browser security warnings flagged the site for suspected phishing, and the domain remained unsafe at last check.
- The team has not disclosed total losses; one user reported a $273,000 drain, while analytics firm Bubblemaps estimated about 35 affected wallets and roughly $23,000 stolen based on early on-chain data.
- Officials credit quick detection and community alerts with limiting impact, underscoring a broader rise in front-end phishing attacks across crypto.