Share this article

Solana Meme Coin Factory Pump.Fun Compromised by 'Bonding Curve' Exploit

The exploiter may not be making any money from the attack.

Updated May 16, 2024, 6:43 p.m. Published May 16, 2024, 6:28 p.m.
Solana Hacker House in Miami (Danny Nelson/CoinDesk)
Solana Hacker House in Miami (Danny Nelson/CoinDesk)

The Solana blockchain's red-hot meme coin factory Pump.Fun descended into chaos Thursday at the hands of an exploiter who compromised the tech central to its issuance of joke cryptocurrencies.

"We are aware that the bonding curve contracts have been compromised and are investigating the matter," the months-old project's Twitter account announced two hours into the chaos. "We’ve paused trading – you cannot buy and sell any coins at the moment."

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

Trading has been paused for now, according to Pump.fun, but prior to the announcement, traders were left to speculate on what was happening on the platform.

Details of the attack were still coming together at press time.

According to people who are helping with the early stages of the investigation, an exploiter was using a combination of trading tactics to overwhelm Pump.fun and seemingly corner the market for dozens of meme coins. Oddly, on-chain evidence suggests the attacker was not making much of a profit. The people spoke with CoinDesk on the condition of confidentiality since the inquiries are still preliminary.

Pump.fun is a months-old project for creating and gambling on meme coins on the Solana blockchain. It advertises itself as a "fair launch" platform where investors can buy into joke tokens in their earliest moments. Coins sometimes hit it big for their investors, but most implode before they reach the critical market cap of $69,000 where tokens get released into the wild.

Thursday's exploit hit smart contracts responsible for issuing the meme coins on Pump.Fun curve, people said. The attacker tricked the platform's bonding curve into accepting phantom SOL tokens they had borrowed and quickly repaid in what's known as a "flash loan." This resulted in the bonding curves filling up with nonexistent SOL, making tokens look valuable despite no real buy-side interest.

The attacker has caused losses of $300,000 in SOL tokens, according to on-chain researchers. Rather than run off with the money, they used it to repay the flash loans and airdrop funds to other people, the people said.

More For You

KuCoin Hits Record Market Share as 2025 Volumes Outpace Crypto Market

16:9 Image

KuCoin captured a record share of centralised exchange volume in 2025, with more than $1.25tn traded as its volumes grew faster than the wider crypto market.

What to know:

  • KuCoin recorded over $1.25 trillion in total trading volume in 2025, equivalent to an average of roughly $114 billion per month, marking its strongest year on record.
  • This performance translated into an all-time high share of centralised exchange volume, as KuCoin’s activity expanded faster than aggregate CEX volumes, which slowed during periods of lower market volatility.
  • Spot and derivatives volumes were evenly split, each exceeding $500 billion for the year, signalling broad-based usage rather than reliance on a single product line.
  • Altcoins accounted for the majority of trading activity, reinforcing KuCoin’s role as a primary liquidity venue beyond BTC and ETH at a time when majors saw more muted turnover.
  • Even as overall crypto volumes softened mid-year, KuCoin maintained elevated baseline activity, indicating structurally higher user engagement rather than short-lived volume spikes.

More For You

How the ultra-wealthy are using bitcoin to fund their yacht upgrades and Cannes trips

wealthtransfer

Cometh founder Jerome de Tychey is applying DeFi lending and borrowing on platforms like Aave, Morpho, and Uniswap to structures that help the ultra-wealthy secure loans against their massive crypto fortunes.

What to know:

  • Wealthy investors who hold much of their fortune in crypto are increasingly turning to decentralized finance platforms to secure flexible credit lines without selling their digital assets.
  • Firms like Cometh help family offices and other rich clients navigate complex DeFi tools, using assets such as bitcoin, ether and stablecoins to replicate traditional Lombard-style collateralized loans.
  • DeFi loans can be faster and more anonymous than traditional bank credit but carry volatility and liquidation risks, and Cometh is also experimenting with applying DeFi strategies to traditional securities via ISIN-based tokenization.