{"id":12199,"date":"2024-04-02T12:34:40","date_gmt":"2024-04-02T09:34:40","guid":{"rendered":"https:\/\/forklog.com\/en\/telegram-bots-bonkbot-and-solareum-users-suffer-520000-losses-due-to-hacks\/"},"modified":"2024-04-02T12:34:40","modified_gmt":"2024-04-02T09:34:40","slug":"telegram-bots-bonkbot-and-solareum-users-suffer-520000-losses-due-to-hacks","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/telegram-bots-bonkbot-and-solareum-users-suffer-520000-losses-due-to-hacks\/","title":{"rendered":"Telegram Bots BONKbot and Solareum Users Suffer $520,000 Losses Due to Hacks"},"content":{"rendered":"<p>The trading Telegram bot BONKbot on the Solana network has reportedly been hacked, resulting in users losing approximately $208,000.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/CertiKInsight?src=hash&#038;ref_src=twsrc%5Etfw\">#CertiKInsight<\/a> ?<\/p>\n<p>We are seeing reports that <a href=\"https:\/\/twitter.com\/bonkbot_io?ref_src=twsrc%5Etfw\">@bonkbot_io<\/a> users have lost funds in a possible private key leak.<\/p>\n<p>Problem may lie in users exporting private keys<\/p>\n<p>Based on reports, it appears that at least ~$208k has been stolen <a href=\"https:\/\/t.co\/JD91fBZNLI\">pic.twitter.com\/JD91fBZNLI<\/a><\/p>\n<p>\u2014 CertiK Alert (@CertiKAlert) <a href=\"https:\/\/twitter.com\/CertiKAlert\/status\/1773711057741062158?ref_src=twsrc%5Etfw\">March 29, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Analysts at CertiK noted multiple reports of losses and suggested a probable private key leak.<\/p>\n<p>The exact cause of the exploit remains unknown. Representatives of BONKbot and other users point to different culprits.<\/p>\n<p>According to the Telegram bot developers, the issue arose because users exported their private keys, which were then compromised in another application.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">TLDR: BONKbot is SAFE, as always, and exporting your private key itself did NOT put you at risk. There has been an exploit with another Solana app.<\/p>\n<p>More than half of the ~300 victims were non-BONKbot wallets.<\/p>\n<p>The BONKbot users affected had imported their private key into a\u2026<\/p>\n<p>\u2014 BONKbot (@bonkbot_io) <a href=\"https:\/\/twitter.com\/bonkbot_io\/status\/1773769443845574764?ref_src=twsrc%5Etfw\">March 29, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cBONKbot remains safe, and exporting the private key itself does not put you at risk. A vulnerability has been noted in another Solana application. More than half of the approximately 300 victims were non-BONKbot wallets,\u201d the post stated.<\/p>\n<\/blockquote>\n<p>Meanwhile, traders who did not export keys also reported losses.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">My bonkbot wallet got drained. And, contrary to what the devs claim, my wallet was not linked to any other app (except sol-incinerator). The private key was only exported to Phantom.<br \/>If you want to help me a little bit to get back on track:\u2026 <a href=\"https:\/\/t.co\/ywxWFZ6TX9\">pic.twitter.com\/ywxWFZ6TX9<\/a><\/p>\n<p>\u2014 marc611 | TheYoloDAO (@marctheyolo) <a href=\"https:\/\/twitter.com\/marctheyolo\/status\/1773679298487935096?ref_src=twsrc%5Etfw\">March 29, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cMy BONKbot wallet was drained. Contrary to the developers&#8217; claims, my wallet was not linked to any other app (except sol-incinerator). The private key was only exported to Phantom,\u201d stated marc611.<\/p>\n<\/blockquote>\n<p>In BONKbot, the blame was placed on a \u201cspecific application,\u201d with some pointing to Solareum, another Solana-based Telegram bot.<\/p>\n<p>Representatives of the latter deny any vulnerabilities and claim the exploit may be more widespread, affecting other bots and decentralized applications.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">solareum devs confirm they are closing the project<\/p>\n<p>Full message in next tweet <a href=\"https:\/\/t.co\/xqHtgxVfwG\">pic.twitter.com\/xqHtgxVfwG<\/a><\/p>\n<p>\u2014 king.sol (@DeFiAzog) <a href=\"https:\/\/twitter.com\/DeFiAzog\/status\/1774133453572727021?ref_src=twsrc%5Etfw\">March 30, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>They suggested hackers might have stolen access tokens to the Telegram bot, gaining control over the message history containing private keys. The damage was estimated at approximately $310,000.<\/p>\n<p>Days after the incident, Solareum announced its closure. Developers cited \u201cinsufficient funds, evolving market trends, and the recent security breach.\u201d<\/p>\n<p>The bot team has already contacted law enforcement in an attempt to freeze the stolen funds if they reach centralized exchanges.<\/p>\n<p>The situation has caused confusion in the community, as the nature of the vulnerability remains unclear. The number of affected users also remains unknown: BONKbot claims only 0.1% of their traders were impacted, while some users suggest much higher figures.<\/p>\n<p>Bans in the BONKbot chat for expressing concerns have further diminished trust in such statements.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Hey <a href=\"https:\/\/twitter.com\/bonkbot_io?ref_src=twsrc%5Etfw\">@bonkbot_io<\/a> is this how you deal with real situations? when your clients loses hundreds of thousands. Your admin team literally kicking everyone speaking up. And you tell us this is safe continue to use it?<\/p>\n<p>You fucking scammers I will take you down myself <a href=\"https:\/\/t.co\/JCKlGrbmal\">pic.twitter.com\/JCKlGrbmal<\/a><\/p>\n<p>\u2014 shrek (@ShrekCrypto_) <a href=\"https:\/\/twitter.com\/ShrekCrypto_\/status\/1773647093015404783?ref_src=twsrc%5Etfw\">March 29, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cHey, BONKbot, is this how you handle real situations when your clients lose hundreds of thousands? Your admin team is literally kicking everyone who speaks up. And you tell us this is safe and suggest we continue using [the bot]? You ***ing scammers, I will take you down myself,\u201d wrote a disgruntled trader.<\/p>\n<\/blockquote>\n<p>In March, according to PeckShield, crypto projects lost assets worth $187 million due to hacks. This figure decreased by 48% compared to the previous month.<\/p>\n<p>According to Immunefi research, in the first quarter, losses from fraud and hacking in the industry <a href=\"https:\/\/forklog.com\/en\/news\/crypto-industry-faces-336-million-loss-from-hacks-and-scams\">reached $336 million<\/a>. The losses are 100% linked to the DeFi sector.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The trading Telegram bot BONKbot on the Solana network has reportedly been hacked, resulting in users losing approximately $208,000. #CertiKInsight ? We are seeing reports that @bonkbot_io users have lost funds in a possible private key leak. Problem may lie in users exporting private keys Based on reports, it appears that at least ~$208k has [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12198,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[44,723,1290],"class_list":["post-12199","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybercrime","tag-telegram","tag-trading-bots"],"aioseo_notices":[],"amp_enabled":true,"views":"92","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/12199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=12199"}],"version-history":[{"count":0,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/12199\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/12198"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=12199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=12199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=12199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}