Skip to content
Bonk.fun Domain Hijacked in Wallet-Draining Phishing Attack

Bonk.fun Domain Hijacked in Wallet-Draining Phishing Attack

First seen 12 Mar 2026, 11:40 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 24, 2026 at 00:43 UTC
  • •Bonk.fun's domain was hijacked, leading to a wallet-draining phishing attack.
  • •Only users who signed the fake terms-of-service after the compromise were affected.
  • •The Bonk.fun team is actively addressing the situation and warning users.

On March 12, 2026, the Bonk.fun domain was hijacked by hackers who deployed a wallet-draining phishing prompt. The attack compromised a team account, allowing attackers to push a malicious terms-of-service message that prompted users to authorize transactions draining their crypto wallets. The Bonk.fun team quickly warned users against interacting with the site, stating that only those who signed the fake TOS message after the compromise were affected. Users who had previously connected their wallets or traded tokens were not impacted. The exact number of affected users and the total funds lost have not been disclosed. The incident highlights the ongoing threat of phishing attacks in the cryptocurrency space, where malicious websites can lead to significant financial losses. The Bonk.fun team is actively working to resolve the situation and restore user trust.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 201d ago How this analysis works

Timeline

2026-03-12
Bonk.fun domain hijacked and phishing prompt deployed
2026-03-12
Bonk.fun team warns users not to interact with the site
2026-03-12
Users report losses after signing the fake TOS message

More articles in this cluster (13)