Yesterday wasn't a fun day for Pump.fun
If you don't know what Pump.fun is, it is a platform where you can launch a token with 0.02 SOL and where many scammers are thriving to launch tokens they nuke to zero.
Yesterday a former employee (@STACCoverflow on Twitter, doxxed too) launched an attack to the website.
Pump.fun explained in better words what happen:
Here is the detailed rundown of what happened:
At 15:21 UTC, a former employee, having illegitimately taken access of the withdraw authority using their privileged position at the company, used flash loans on a Solana lending protocol to:
1. Borrow SOL (flash loans with Marginfi)
2. Use that SOL to buy up as many coins as they can so these coins hit 100% on their respective bonding curves
3. Once these coins hit 100%, gain access to the bonding curve liquidity
4. Repay flash loans, by 17:00 UTC, all trading on http://pump.fun was halted.
Out of a total of $45m of liquidity in the bonding curve contracts, only ~$1.9m was affected
A lot of people were happy about what happen cause they thought that pump.fun would cease to exist, but the team responded pretty quickly to the situation, halting the website, right now it is back to normal.
At the moment of writing it's not clear where the 2M dollars went and if they were actually stolen by the attacker or not.
The situation it went absurd when it was clear who the attacker was and that he is fully doxxed.
He started tweeting weird stuff like:
https://x.com/STACCoverflow/status/1791134470071865576
Honestly this stuff happens only in Crypto, I don't know if pump.fun will seek any criminal charges against him, but I will keep following the situation cause it is too absurd to not follow it.