pump.science Private Key leaked, fake coins launched Market Cap soared to tens of millions of dollars at one point

robot
Abstract generation in progress

Original title: 'pump.science WalletPrivate Key Leakage: An Unfinished Storm'

Original author: Karen, Foresight News

On the evening of November 25th, Urolithin B (URO) Token, labeled as the creator of RIF and URO on pump.fun, made many community members mistakenly believe that it was the official Token issuance of pump.science. Urolithin B (URO) quickly 'graduated' and its Market Cap soared to $10 million within two minutes after joining the liquidity pool. However, it began to decline continuously afterwards, and its Market Cap has now fallen to about $100,000.

This event also seems to have affected the market performance of Urolithin A (URO) and Rifampicin (RIF), both of which have dropped more than 30% in the past 24 hours. So, what exactly is going on?

pump.science Wallet private key pair leaked

The event was caused by the leakage of the wallet private key of pump.science.

According to the official statement from pump.science, due to an oversight in its GitHub repository, the WalletAddress T5j2UBTvLYPCwDP5MVkSALN7fwuLFDL9jUXJNjjb8sc was attacked and the attacker found the Secret Key pair in the website's Source Code. The Secret Key pair was originally used for testing purposes in pump.science's GitHub from the start, and the development team was not aware of its importance.

From the scam URO Token page that appeared on pump.fun last night, it can be seen that the Wallet Address that deployed this fake Token is T5j2UBTvLYPCwDP5MVkSALN7fwuLFDL9jUXJNjjb8sc. According to pump.fun, this Address has off-chain deployed the two official Tokens Urolithin A (URO) and Rifampicin (RIF), with current Market Caps of approximately 87 million USD and 37 million USD, respectively.

The URO Token scam this time was carried out using an Address starting with T5j2UBT, which leaked the Secret Key. This is why the deployment of the official URO and RIF Tokens is shown on pump.fun as an on-chain issuance of new coins by the deployer.

pump.science私钥泄露,假币上线市值一度飙升至千万美元

pump.science indicates that the Wallet is marked as the off-chain Token creator for URO and RIF on pump.fun, and attackers may use this Wallet to issue more Tokens. In addition to URO and RIF, any other Tokens issued by this Wallet should be considered fraudulent.

It is worth noting that the official pump.science has not taken any remedial or compensatory measures for those who mistakenly believed and dumb buying the fraudulent URO Token, which has caused widespread follow and discussion in the community.

pump.fun off-chain creation function causes chaos in blockchain browsers and data tools

What also caused confusion in the community is the display of the Token creator in pump.fun, blockchain browser, and data tools.

pump.science official URO and RIF Token are created through pump.fun off-chain, while the fraudulent URO is created through pump.fun on-chain. However, the blockchain explorer solscan shows that the deployer Address of Urolithin A (URO) and Rifampicin (RIF) is: BLDRZQiqt4ESPz12L9mt4XTBjeEfjoBopGPDMA36KtuZ.

pump.science私钥泄露,假币上线市值一度飙升至千万美元

pump.science私钥泄露,假币上线市值一度飙升至千万美元

Next, let's first understand the off-chain launch coin function of pump.fun. On the pump.fun platform, the off-chain launch coin is free, and it will not be recorded on-chain immediately after Token issuance, it will only be recorded on-chain when the first buyer appears. The first buyer needs to pay the Token issuance cost. Therefore, for Tokens created off-chain, the first buyer is usually mistakenly recognized as the deployer of the Token by blockchain browsers such as solscan or GMGN and other data tools.

For example, after the official URO and RIF Token are created off-chain, the WalletAddress BLDRZQiqt4ESPz12L9mt4XTBjeEfjoBopGPDMA36KtuZ of the first buyer is mistakenly marked as the deployer of the Token by solscan or GMGN.

Here, the author reminds investors to distinguish and verify the Meme Tokens created on-chain and off-chain at pump.fun, to avoid falling into fraud traps. In addition, it is also necessary to remain vigilant regarding any potential Tokens with Walletissuance starting with T 5 j 2 UBTvLY leaked by pump.science. At the same time, we also hope that platform operators and Token deployers can enhance security measures to prevent such fraudulent behavior from happening again.

Original link

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)