Skip to content
← Back to newsPump Science Issues Apology Following Fraud Token Incident
Security

Pump Science Issues Apology Following Fraud Token Incident

By ToTo BugelmanNewcomer0 rep· 11/28/2024

Decentralized science platform Pump Science has issued a public apology after a significant security breach led to the creation of fraudulent tokens. The incident was attributed to a leaked private key on GitHub, which allowed a hacker to exploit the platform's profile and generate unauthorized tokens.

 

Key Takeaways

  • Pump Science's private key was leaked on GitHub, leading to fraudulent token creation.

  • The company has changed its profile name to prevent further scams.

  • A partnership with blockchain security firm Blockaid has been established for future protection.

 

Incident Overview

On November 27, during an ask-me-anything (AMA) session, Pump Science’s Benji Leibowitz acknowledged the severity of the situation, stating, "We do not want to diminish how much of a screw-up this was." He emphasized that the company would never launch tokens on the compromised Pump.fun profile again.

The breach occurred when the private keys linked to the Pump.fun profile were inadvertently exposed on GitHub. This oversight allowed a known attacker to create fraudulent tokens, including Urolithin B through to Urolithin E ($URO) and Cocaine ($COKE). In response, Pump Science urged users to avoid any new tokens launched from the compromised profile, clarifying that these tokens were not created by their team.

 

Response Measures

To mitigate the fallout from this incident, Pump Science has taken several immediate actions:

  • Profile Name Change: The Pump.fun profile has been renamed to "dont_trust" to deter users from purchasing fraudulent tokens.

  • Partnership with Blockaid: The company has partnered with blockchain security firm Blockaid to monitor and flag any new mints originating from the compromised address.

  • Audit and Security Enhancements: Pump Science plans to conduct a complete audit of its front end and implement a bug bounty program for penetration testing. Future token launches will only occur after thorough audits of the app and smart contracts.

 

Blame and Accountability

Pump Science partially attributed the leak to BuilderZ, a Solana-based software firm, which mistakenly left the private key for the developer wallet in its GitHub codebase. However, the company clarified that the attacker could not have been BuilderZ, as the method used to bring the tokens onto Solana’s chain differed from their processes.

Instead, Pump Science suspects that the hacker may be linked to a previous incident involving James Pacheco, a founder of the Solana-based commodity tokenization platform "elmnts."

 

Future Outlook

Looking ahead, Pump Science aims to restore user trust and enhance its security protocols. The company is committed to ensuring that new tokens will only be launched after comprehensive audits are completed, with hopes to have these measures in place by the holiday season.

Pump Science specializes in trading tokens associated with longevity medicines, with its current offerings being Rifampicin (RIF) and Urolithin A (URO). These tokens have market caps of $85.6 million and $37.2 million, respectively, according to CoinGecko data. Rifampicin is primarily used to treat tuberculosis, while Urolithin A is recognized for its potential health benefits as a dietary supplement.

As the decentralized science sector continues to evolve, incidents like this highlight the critical importance of security and transparency in the blockchain space.

 

Sources

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Pump Science Issues Apology Following Fraud Token Incident | BlockzHub