Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Former Pump.fun Employee Exploits Withdrawal Authority, Causes $1.9M Loss

Former Pump.fun Employee Exploits Withdrawal Authority, Causes $1.9M Loss

CryptopotatoCryptopotato2024/05/17 17:55
By:Chayanika DekaMore posts by this author

Pump.fun outlined plans to compensate affected users from the exploit.

Solana-based meme coin launchpad Pump.fun announced that a former employee used their “privileged position” to access “withdraw authority” and misappropriated around 12,300 SOL, worth approximately $1.9 million at the time.

To prevent further damage, Pump.fun halted trading and updated the contracts.

Flash Loan Exploit

Addressing the exploit, Pump.fun said in an X post that a former employee misused their access to the withdrawal authority, which they had obtained through their previous position within the company.

Utilizing flash loans on a Solana lending protocol, the individual in question borrowed SOL and bought up coins to push them to 100% on their bonding curves. This allowed them to access the bonding curve liquidity and repay the flash loans.

Trading on the platform was halted a few hours later. Out of $45 million in total liquidity, approximately $1.9 million was affected. The Pump.fun team then redeployed the contracts and resumed trading with a 0% fee for the next seven days.

The meme coin creation platform further noted that the tokens that reached 100% during the exploit are currently in limbo and untradeable until liquidity pools are deployed for them on the Solana lending protocol, Raydium. To compensate users, the team said it will replenish the liquidity pools for the affected coins with an equal or greater amount of SOL within the next 24 hours.

“Please bear with us as we aim to resume the trading of these coins in a safe and structured manner. We have been working with some of the most esteemed security folks in the space to not only minimize the impact of the situation, but to ensure that this will never happen in the future.”

Internal Private Key Leak

Before Pump.fun’s announcement, cryptocurrency market maker Wintermute’s head of research, Igor Igamberdiev, attributed the hack to an internal private key leak and suspected X user “STACCoverflow.”

Shortly thereafter X user “Stacc” admitted to executing the exploit, criticizing their “horrible bosses” at Pump.fun, describing them as unsuitable “face of the blockchain” community.

You Might Also Like:

  • Record Number of New Traders Flock to Meme Coins: Data
  • a16z Partner Questions Favoritism Towards Meme Coins Over Blockchain Innovation
  • CryptoQuant CEO Warns Against Meme Coin Hype: A Threat to Industry Progress?
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

BTC/ETH VIP Earn Ultimate Carnival is officially here!

Bitget Announcement2025/09/18 07:12

New spot margin trading pair — FLOCK/USDT!

Bitget Announcement2025/09/18 06:55

0GUSDT now launched for pre-market futures trading

Bitget Announcement2025/09/18 05:39