pump.science Private Key Lost: The Full Story of Counterfeit Currency Launch and Collapse

robot
Abstract generation in progress

On the evening of November 25th, a token called Urolithin B (URO), marked as the creator's address issuance on pump.fun, was mistakenly thought by many community members to be the official token issuance of pump.science. Urolithin B (URO) quickly 'graduated' and its market capitalization soared to $10 million within two minutes after joining the liquidity pool. However, it has since been continuously declining, and the current market capitalization has fallen to about $100,000.

This event seems to have also affected the market performance of Urolithin A (URO) and Rifampicin (RIF), both of which have fallen more than 30% in the past 24 hours. So what's going on?

pump.science Wallet Private Key Pair Leaked

The incident was caused by the leakage of the wallet private key of pump.science.

According to pump.science, due to an oversight in its GitHub repository, the WalletAddress T5j2UBTvLYPCwDP5MVkSALN7fwuLFDL9jUXJNjjb8sc was attacked and the attacker found the Secret Key pair in the website's Source Code. The Secret Key pair was initially used for testing purposes on pump.science's GitHub and the development team was unaware of its importance.

From the fraudulent URO Token page that appeared on pump.fun last night, it can be seen that the WalletAddress deploying this fake Token is T5j2UBTvLYPCwDP5MVkSALN7fwuLFDL9jUXJNjjb8sc. According to pump.fun, this Address has deployed the official Tokens Urolithin A (URO) and Rifampicin (RIF) off-chain, with current Market Caps of approximately 87 million USD and 37 million USD respectively.

And this scam URO Token is on-chain issuance by leaking the Secret Key pair of the Address starting with T5j2UBT. This is why it is displayed as the official URO and RIF Token deployer releasing new coins on pump.fun.

pump.science indicates that the Wallet is marked as the off-chain Token creator for URO and RIF on pump.fun, and attackers may exploit this Wallet to issue more Tokens. In addition to URO and RIF, any other Tokens issued by this Wallet should be considered fraudulent.

It is worth noting that the official pump.science has not taken any remedial or compensatory measures for those who mistakenly believed and dumb buying URO Token, which has caused widespread follow and discussion in the community.

pump.fun off-chain creation function causes confusion in blockchain browser and data tool display

What also caused confusion in the community was the display of 'pump.fun' in the blockchain browser and data tools, as well as the creator of the 'Token'.

pump.science official URO and RIF Token are created through pump.fun off-chain, while the fraudulent URO is created through pump.fun on-chain. However, the blockchain browser solscan shows that the deployer Address of Urolithin A (URO) and Rifampicin (RIF) is: BLDRZQiqt4ESPz12L9mt4XTBjeEfjoBopGPDMA36KtuZ.

Next, let's take a look at the off-chain launch coin function of pump.fun. On the pump.fun platform, off-chain launch coin is free, and it will not be recorded on-chain immediately after Token issuance until the first buyer appears. The first buyer needs to pay the issuance cost of Token. Therefore, for Tokens created off-chain, the first buyer is usually mistaken by data tools such as solscan or GMGN blockchain browser as the deployer of the Token.

For example, after the official URO and RIF Token are created off-chain, the WalletAddress BLDRZQiqt4ESPz12L9mt4XTBjeEfjoBopGPDMA36KtuZ of the first buyer is incorrectly marked as the deployer of the Token by solscan or GMGN.

Here, the author reminds investors to distinguish and verify the Meme Tokens created on-chain and off-chain at pump.fun to avoid falling into scams. In addition, they also need to remain vigilant about any potential Tokens with Walletissuance starting with T5j2UBTvLY leaked by pump.science. At the same time, we also hope that the platform and Token deployers can enhance security measures to prevent such fraudulent activities from happening again.

Original link

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)