Pump.fun pauses trading after apparent flash loan attack

Pump.fun is “aware” that bonding curve contracts on Pump.fun were exploited, and has since paused trading

article-image

Dall-e modified by Blockworks

share

Pump.fun was attacked Thursday by an exploiter who seemingly used flash loans to buy out the bonding curve. 

In a post on X, Pump.fun said that it was “aware” that the contracts were compromised and were investigating. 

“We have upgraded the contracts so the attacker cannot siphon any more funds. The TVL in the protocol right now is safe,” the team said. “We’ve paused trading — you cannot buy and sell any coins at the moment. Any coins that are currently in the process of migrating to Raydium cannot be traded and will not be migrating for an indefinite period of time.”

Igor Igamberdiev, head of research at Wintermute, analyzed the situation in a series of posts on X, saying that the key was compromised, “though the possibility of an inside job remains.”

Loading Tweet..

Igamberdiev said that the amount lost by Pump.fun is “at least” 12,000 SOL, or roughly $2 million.

An account on X going by Stacc seemed to take credit for the attack, writing “I’m about to change the course of history” in a post

Stacc seemed to imply in his posts that he didn’t intend to keep the stolen funds, but rather planned to transfer the “remaining balances of bonding curves” to some token users. 

Loading Tweet..

It’s not clear as of publication how Stacc was able to execute the attack, or if they’re distributing the balances to random people. 

As Blockworks previously reported, Pump.fun lets developers launch tokens without seed liquidity for a couple of dollars. Its revenue comes from users buying and selling tokens. 

Tokens that exceed market caps of $69,000 can then be listed on the Raydium DEX. 

This is a developing story.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the Forward Guidance newsletter.

Get alpha directly in your inbox with the 0xResearch newsletter — market highlights, charts, degen trade ideas, governance updates, and more.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research

article-image

Jack explored the various AI and memecoin projects that have sprung up over the past month

article-image

If gold remains steady today, a single move from bitcoin to $98,500 would do it

article-image

Revenue estimates for the third quarter come in at $33 billion, which would be an 83% increase from the prior year

article-image

Senator Cynthia Lummis hopes a US strategic bitcoin reserve can be teed up for “adoption in 2025”

article-image

As EIP-4844 “blobs” transform the economics of Ethereum layer-2s, a growing debate pits long-term scalability against immediate ETH value

article-image

Prosecutors argued that FTX co-founder Gary Wang cooperated in their case against former FTX CEO Sam Bankman-Fried