Pump.fun pauses trading after apparent flash loan attack

Pump.fun is “aware” that bonding curve contracts on Pump.fun were exploited, and has since paused trading

article-image

Dall-e modified by Blockworks

share

Pump.fun was attacked Thursday by an exploiter who seemingly used flash loans to buy out the bonding curve. 

In a post on X, Pump.fun said that it was “aware” that the contracts were compromised and were investigating. 

“We have upgraded the contracts so the attacker cannot siphon any more funds. The TVL in the protocol right now is safe,” the team said. “We’ve paused trading — you cannot buy and sell any coins at the moment. Any coins that are currently in the process of migrating to Raydium cannot be traded and will not be migrating for an indefinite period of time.”

Igor Igamberdiev, head of research at Wintermute, analyzed the situation in a series of posts on X, saying that the key was compromised, “though the possibility of an inside job remains.”

Loading Tweet..

Igamberdiev said that the amount lost by Pump.fun is “at least” 12,000 SOL, or roughly $2 million.

An account on X going by Stacc seemed to take credit for the attack, writing “I’m about to change the course of history” in a post

Stacc seemed to imply in his posts that he didn’t intend to keep the stolen funds, but rather planned to transfer the “remaining balances of bonding curves” to some token users. 

Loading Tweet..

It’s not clear as of publication how Stacc was able to execute the attack, or if they’re distributing the balances to random people. 

As Blockworks previously reported, Pump.fun lets developers launch tokens without seed liquidity for a couple of dollars. Its revenue comes from users buying and selling tokens. 

Tokens that exceed market caps of $69,000 can then be listed on the Raydium DEX. 

This is a developing story.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates.png

Research

USDai is a synthetic dollar fully backed by tokenized three‑month T-bills custodied by M^0. When holders stake USDai in an ERC-4626 vault, they mint sUSDai, which finances short-term, amortizing loans secured by NVIDIA-class GPUs and servers.

article-image

After a jittery few months, recent economic data is hinting at a resilient economy that is beginning to re-accelerate

article-image

The stablecoin bill now heads to the president’s desk

article-image

The House on Thursday passed the CLARITY Act, a landmark cryptocurrency market structure bill

article-image

Interchain Labs will focus on sovereign L1s and institutional demand, abandoning plans for smart contracts on the Cosmos Hub

article-image

Also, only three tokens have outperformed bitcoin so far this year: XMR, HYPE and SKY

article-image

The fund group has submitted proposals in recent months for other funds that would hold litecoin, solana, XRP, HBAR, Sui and others