pump.fun Hack

Reported loss $2.0M
Solana
Private Key Compromised (Unknown Method)

What happened

Pump.fun attributed its bonding-curve exploit to a former employee who obtained withdrawal authority through privileged access. Flash loans funded token purchases that completed affected bonding curves and enabled liquidity extraction. The team halted trading, upgraded the contracts, and announced replacement liquidity for affected coins.

Technical root cause

Privileged withdrawal authority enabled the exploit. Flash loans supplied temporary purchase capital, but the disclosed account did not establish a separate arithmetic flaw in bonding-curve pricing.

How it happened

  1. According to Pump.fun, a former employee obtained the platform's withdrawal authority.
  2. The exploiter borrowed SOL through flash loans and bought tokens until affected bonding curves completed.
  3. The resulting liquidity allowed the exploiter to repay the loans and extract funds.
  4. Pump.fun halted trading and upgraded its contracts before reopening.

Protocol details

Classification Infrastructure / Other / Key Compromise
Protocol Type Launchpad
Implementation language Rust/Anchor
Protocol links Website @pumpdotfun

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.