Pump Science apologizes after GitHub key leak leads to fraudulent tokens

Source Cryptopolitan

Pump Science, a decentralized science platform, has apologized to its users after its private key was inadvertently exposed on GitHub. The leaked private key, T5j2UB…jjb8sc, allowed a ‘known attacker’ to hijack the wallet and create fraudulent tokens tied to its Pump.fun profile. 

In a series of X posts from November 25 to November 27, Pump Science disclosed the security breach on one of its wallet addresses and asked its users not to trust any tokens released on its Pump.fun profile. The platform even changed its Pump.fun profile name to “dont_trust” to warn users not to buy any newly launched tokens.

Pump Science revealed the security attack on one of its wallet addresses

The company clarified that the private key, T5j2UBTvLYPCwDP5MVkSALN7fwuLFDL9jUXJNjjb8sc, linked to their Pump.fun profile, was compromised, allowing ‘the known attacker’ to launch fraudulent Urolithin (URO) and Rifampicin (RIF) tokens.  

Pump Science’s Benji Leibowitz, on November 27, in an X AMA session, said, “We do not want to diminish how much of a screw-up this was; we totally acknowledge that this is a huge issue and misstep on our part,” apologizing to the platform’s users.

Benji further guaranteed that such incidents would never occur again and stated that the platform would no longer release tokens on Pump.fun.

Moreover, the DeSci platform has maintained that security will be its top priority. It plans to incorporate consultative and competitive audits on its application and smart contracts. Once all necessary audits are done, any new tokens will be launched next year.

It is even working with blockchain security firm Blockaid to track any new mints from the compromised address.

Pump Science has its suspicions on who the attacker could be

Pump Science pointed to BuilderZ, a Solana-based software company, as partly at fault for the incident. They blamed the firm for leaving the private key for the developer wallet “T5j2U…jb8sc” exposed in their GitHub repository and mistakenly believing it belonged to a test wallet.

However, they explained that, after analyzing the techniques used to launch tokens on Solana’s chain, they did not think BuilderZ was the attacker. 

Pump Science instead believes that the hacker could be the same person or group of people who hacked a wallet owned by James Pacheco, a founder of Solana-based commodity tokenization platform “elmnts.”

Land a High-Paying Web3 Job in 90 Days: The Ultimate Roadmap

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Japanese Yen stands tall near one-month top against USD on hawkish BoJ talksThe Japanese Yen (JPY) rallied to the highest level since early February against its American counterpart on Friday amid bets for an imminent shift in the Bank of Japan's (BoJ) policy stance.
Author  FXStreet
Mar 11, Mon
The Japanese Yen (JPY) rallied to the highest level since early February against its American counterpart on Friday amid bets for an imminent shift in the Bank of Japan's (BoJ) policy stance.
placeholder
Natural Gas sinks to pivotal level as China’s demand slumpsNatural Gas price (XNG/USD) edges lower and sinks to $2.56 on Monday, extending its losing streak for the fifth day in a row. The move comes on the back of China cutting its Liquified Natural Gas (LNG) imports after prices rose above $3.0 in June. It
Author  FXStreet
Jul 01, Mon
Natural Gas price (XNG/USD) edges lower and sinks to $2.56 on Monday, extending its losing streak for the fifth day in a row. The move comes on the back of China cutting its Liquified Natural Gas (LNG) imports after prices rose above $3.0 in June. It
placeholder
FedEx could unlock $10-20bln in shareholder value from potential freight spin-offInvesting.com -- FedEx Corporation (NYSE:FDX) could unlock $10 billion to $20 billion in incremental shareholder value by spinning off its freight business into a standalone company, Barclays (LON:BARC) analysts said in a note.
Author  Investing.com
Yesterday 02: 40
Investing.com -- FedEx Corporation (NYSE:FDX) could unlock $10 billion to $20 billion in incremental shareholder value by spinning off its freight business into a standalone company, Barclays (LON:BARC) analysts said in a note.
placeholder
Is Nvidia Still the Best Artificial Intelligence (AI) Stock to Own for 2025?Nvidia will sell more GPUs in 2025 than in 2024.
Author  The Motley Fool
22 hours ago
Nvidia will sell more GPUs in 2025 than in 2024.
placeholder
FTC probes Uber over subscription service practices, Bloomberg News reportsInvesting.com -- The U.S. Federal Trade Commission is investigating Uber Technologies Inc (NYSE:UBER) over allegations that it enrolled customers into its Uber One subscription service without consent and made it challenging for them to cancel, according to a Bloomberg report.
Author  Investing.com
8 hours ago
Investing.com -- The U.S. Federal Trade Commission is investigating Uber Technologies Inc (NYSE:UBER) over allegations that it enrolled customers into its Uber One subscription service without consent and made it challenging for them to cancel, according to a Bloomberg report.
goTop
quote