Worked example · 2025-02
Solana brand-X-account compromise cohort (Jupiter / Pump.fun / DogWifCoin) — Solana — 2024-11 to 2025-02
- OAK-T4 (Access Acquisition — broad construction) at the external-platform-account-compromise sub-surface. The compromise vector targets the Solana-protocol-brand X account (the brand-side communication channel), not the on-chain protocol itself. The on-chain extraction is mediated by the brand's audience trust — followers see legitimate-looking announcements from a trusted source and act on them. Structurally adjacent to T6.002 (Fake Audit Claim) and T4.002 (Compromised Frontend Permit Solicitation) but operating at a different substrate: the social-media-account-substrate rather than the website / DNS / signing-surface substrate.
- OAK-T11.001 (broad construction) — the X-account-compromise vector is a third-party platform compromise affecting a brand's communication surface. ZachXBT's analysis attributes the compromises to either (a) social-engineering of X employees with fraudulent documents/emails or (b) exploitation of an X internal admin panel. Both vectors implicate X-the-platform's operational security, not the Solana protocols' security. The case is structurally similar to Polymarket's Magic-Labs auth-provider compromises (
examples/2024-09-polymarket-magic-labs-takeover.md) in that the trust-substrate is a third-party platform rather than the on-chain protocol — but operates at the audience-amplification layer rather than the user-authentication layer. - OAK-T15.005 (Operator-Communication-Channel Takeover) — canonical anchor for the brand-X-account sub-shape at cohort scale. The compromised surface is the operator's public communication channel under the operator's brand; the access was used to distribute malicious-contract-address messages under verified-brand identity, which is the structural signature that maps the cohort primarily to T15.005 rather than to T15.004 (per the T15.005 boundary rule on what-the-access-was-used-for).
- OAK-T7 (Laundering) chains via the QinShihuang disguise-memecoin pattern — $1.08M USDC received in a laundering wallet was disguised as memecoin trades through a scam token that traded $26M before Solana memecoin platform interventions blocked it. The disguise-trading pattern is a Solana-native laundering-substrate-extension that operates within memecoin-launchpad infrastructure.
Summary
Between November 2024 and February 2025, three high-profile Solana-protocol-brand X (formerly Twitter) accounts were compromised in a connected cohort campaign promoting fake memecoins to large brand-amplified audiences. Per ZachXBT's on-chain forensic analysis, the three named instances are directly connected on-chain — proceeds laundered across all three campaigns flow through overlapping operator infrastructure.
The cohort instances:
DogWifCoin ($WIF) X account compromise — November 2024. The DogWifCoin official X account was compromised; fake announcements promoted scam memecoins. The compromise is the earliest publicly-traceable instance in the connected cohort per ZachXBT's analysis.
Jupiter DEX X account compromise — February 6, 2025. Solana's leading DEX aggregator Jupiter had its main X account hijacked. Hackers promoted fake memecoins $MEOW and $DCOIN; $MEOW briefly surged past $20M market cap before the liquidity was drained, leaving traders unable to sell. JUP token price dropped 12% during the incident; trading volumes on JUP/BTC and JUP/ETH spiked 300%. Jupiter Mobile's separate X handle warned users that "The main Jupiter Exchange account has been compromised" and advised users not to click links. Jupiter regained control within hours and confirmed that no on-chain protocol funds or customer data were compromised. Co-founder Meow stated the attack originated from a U.S.-based IP address. Funds were laundered through BSC wallets before being returned to Solana for further memecoin disguise-trading.
Pump.fun X account compromise — February 26-27, 2025. Solana memecoin launchpad Pump.fun's main X account was compromised. Hackers promoted a fake "official governance" $PUMP token with a Solana contract address, claiming legitimacy. The fake token's market cap surged to ~$5M during the campaign window. Hackers also taunted the community with a follow-up message asking whether they should create a "legit token on Pump.fun" and call it "Hackeddotfun," promising to pump it to a $100M market cap. Pump.fun regained X-account control after several hours and the malicious tweets were removed.
ZachXBT's forensic thread published on Telegram on February 27, 2025, established the on-chain connection across the three cohort instances. Per ZachXBT, $1.08M in USDC flowed into a single operator-cluster wallet from the Pump.fun campaign alone, which was then bridged from BSC to Solana and laundered through the QinShihuang scam memecoin (~$26M cumulative disguise-trading volume) before the Solana memecoin platform intervened to block the token. The same operator-cluster fingerprint appears in the Jupiter and DogWifCoin laundering paths.
The cohort vector — per ZachXBT's analysis — is not a Solana-protocol-side compromise. ZachXBT explicitly states: "[the attacks] are likely not the fault of either the Pump.fun or Jupiter teams." Rather, the attribution-strong vector is X-platform-side exploitation: either social-engineering of X employees with fraudulent documents/emails, or exploitation of an X internal admin-panel surface that allows account-control transfer without the legitimate account holder's authorisation.
The structural shape is therefore: third-party-platform-substrate compromise → brand-amplified-audience deception → Solana-native fast-extraction substrate → cross-chain laundering with disguise-memecoin pattern. The on-chain extraction surface is the Solana-memecoin / Raydium-pool substrate; the trust-substrate-compromise surface is X-platform; the laundering substrate spans Solana / BSC with the QinShihuang disguise-token pattern as a Solana-native laundering primitive.
Why this is structurally significant
The Solana brand-X-account-compromise cohort is structurally distinct from prior crypto-X-account-compromise cases in three ways:
The on-chain-extraction-substrate fit is structurally tight. Crypto X-account compromises predate this cohort (most major exchanges have experienced isolated incidents), but historically the operator-side extraction surface has been relatively narrow — phishing-link distribution, scam-airdrop announcements with limited adoption. The 2024-2025 Solana cohort exploits the Solana-memecoin / Raydium-pool / pump.fun substrate as the extraction primitive, where fake-token deployment is sub-$100, pool-seeding is sub-$1K, and audience-driven price-pump can produce $5-20M market cap within hours. The combination of (a) brand-amplified audience trust, (b) Solana-native fast-deployment economics, and (c) memecoin pump-cycle dynamics produces a structurally-tighter on-chain-extraction fit than prior X-account-compromise cases.
The cross-instance operator-cluster fingerprint is established by independent forensics. ZachXBT's thread explicitly establishes the on-chain linkage across three named instances. The cohort attribution is therefore stronger than per-instance attribution — even where any individual instance might appear to be an isolated incident, the cross-instance laundering-cluster fingerprint demonstrates a sustained operator cohort. This is the canonical 2024-2025 example of cohort-scale X-account-compromise as a discrete attack class, not a sequence of unrelated isolated incidents.
The trust-substrate-locus is X-the-platform's internal admin surface. Per ZachXBT's analysis (and Jupiter co-founder Meow's confirmation that the Jupiter attack originated from a U.S.-based IP), the operator-side leverage was X-platform-side rather than crypto-protocol-side. This is structurally informative: defender-side intervention for the cohort requires X-platform-side hardening (phishing-resistant 2FA enforcement, internal admin-panel access controls), not crypto-protocol-side hardening. The class is therefore a
Defender-intervention-surface-not-on-chainTechnique class — the on-chain-extraction is real and observable but the binding intervention is at a different substrate. This is structurally adjacent to the Polymarket / Magic Labs auth-provider cases (examples/2024-09-polymarket-magic-labs-takeover.md) where the trust-substrate is also off-chain (auth-provider security, X-platform security) but produces on-chain extraction.
The case generalises beyond Solana to any crypto brand with a high-amplification X account. The 2024-2025 cohort happens to concentrate on Solana brands because (a) Solana's memecoin ecosystem provides the tightest on-chain-extraction-substrate fit and (b) the operator-cluster's Solana-native laundering tradecraft (QinShihuang disguise-trading) is calibrated for the Solana ecosystem. Future X-account-compromise cohorts on other chains will likely produce similar structural shapes adapted to those chains' fast-extraction substrates.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2024-11 | DogWifCoin ($WIF) X account compromised; fake announcements promoting scam memecoins; cohort-precursor instance per ZachXBT's later forensic linkage | (cohort genesis surface) |
| 2025-02-06 | Jupiter DEX X account compromised; $MEOW and $DCOIN scam memecoins promoted; $MEOW briefly exceeds $20M market cap before liquidity drain; JUP token price drops 12% | Cohort instance 2 |
| 2025-02-06 | Jupiter Mobile X handle warns users; Jupiter regains main account control within hours; co-founder Meow confirms attack originated from U.S.-based IP; no on-chain protocol funds compromised | (operator response — Jupiter) |
| 2025-02-06 → days | Jupiter post-incident laundering: funds shifted through BSC wallets and back to Solana for further memecoin disguise-trading | T7 cross-chain laundering |
| 2025-02-26 / 2025-02-27 | Pump.fun X account compromised; fake $PUMP "official governance" token promoted with Solana contract address; market cap surges to ~$5M; community taunted with "Hackeddotfun" follow-up | Cohort instance 3 |
| 2025-02-27 | ZachXBT publishes Telegram thread documenting compromise; explicitly establishes on-chain forensic linkage across Pump.fun, Jupiter, and DogWifCoin instances; attributes vector to X-platform-side social-engineering or admin-panel exploitation | Cohort attribution surface |
| 2025-02-27 → days | Pump.fun regains X-account control; malicious tweets removed; $1.08M USDC tracked in single laundering wallet; QinShihuang scam memecoin used as disguise-trading vehicle (~$26M cumulative volume before block) | T7 disguise-memecoin laundering primitive |
| 2025-02 onward | Cointelegraph, CoinMarketCap Academy, Decrypt, KuCoin, Coinspeaker publish secondary coverage; X-account-compromise-cohort framing enters general crypto-press lexicon | (forensic + journalism surface) |
| 2025 onward | Cohort surface remains active across Solana brand X accounts; isolated additional instances continue across the 2025 calendar year | (continuing surface) |
What defenders observed
- Pre-event (X-platform-substrate layer): the X-platform internal admin-panel and customer-support workflow are not directly hardened against social-engineering at the substrate level. Phishing-resistant 2FA enforcement for verified-account-holders is partially implemented but not universally enforced; the internal admin-panel surface is not publicly documented at the granular level required for crypto-brand defender-tooling. Defender lesson: brand-side communication-channel hardening must include diversification to channels that are not single-point-of-failure under X-platform compromise; cryptographically-signed on-chain announcements (e.g., signed messages from a brand-controlled signing address) provide a corroborating channel that compromised X-account messages cannot replicate.
- At-event (audience-deception layer): the brand-amplified audience treats X-account messages as authoritative. Followers of Jupiter / Pump.fun / DogWifCoin had explicit trust in messages from those accounts; the malicious-message reach was bounded by the account's follower count and engagement patterns, both of which were structurally large for these high-profile brands. Defender lesson: audience-side skepticism of high-impact X announcements (token launches, governance changes, contract-address publications) is the user-side intervention layer; brands should publish explicit security advisories that train users to require multi-channel corroboration for high-impact announcements.
- At-event (on-chain-extraction layer): the Solana-memecoin / Raydium-pool / pump.fun substrate provided the fast-extraction primitive. Fake $PUMP and $MEOW tokens were deployed and pumped within hours of the X-account-compromise; the realised retail-loss accumulated during the brief account-compromise window. Defender lesson: Solana-side wallet / aggregator UX layers should surface "newly-deployed token from unverified deployer cluster" warnings against tokens that arrive via X-amplified announcements; this is a UX-layer integration with deployer-cluster-attribution analytics.
- Post-event (laundering-substrate layer): the QinShihuang disguise-memecoin pattern is a Solana-native laundering primitive — proceeds are routed through a scam memecoin's pool to "trade" them through high-volume disguise-pumping before the Solana platform intervenes to block the token. Defender lesson: cross-platform Solana-memecoin coordination (Pump.fun, Raydium, wallet-side blocklists) is the canonical defender-intervention surface for disguise-memecoin laundering; the cohort's persistence demonstrates that platform-side intervention currently lags the operator-side disguise-trading speed.
- Post-event (cohort-attribution surface): ZachXBT's cross-instance forensic linkage was the load-bearing attribution work. The cohort-scale framing — three instances connected on-chain — is structurally stronger than per-instance framing because it establishes operator-cohort persistence. Defender lesson: independent on-chain investigators (ZachXBT and equivalent) are the dominant cohort-attribution surface for X-account-compromise cohorts; brand-side and platform-side coordination with on-chain forensic researchers should be a first-class defender-tooling priority.
What this example tells contributors writing future Technique pages
- X-account-compromise is a discrete attack class with on-chain extraction. Future T4 / T11.001-adjacent contributors should preserve the "third-party-platform compromise → brand-amplified-audience deception → fast-extraction-substrate" chain as a discrete sub-class. The Solana 2024-2025 cohort is the canonical worked example.
- The trust-substrate-locus distinction matters for defender-intervention framing. When the trust-substrate is off-chain (X-platform internal admin surface), on-chain-protocol hardening does not solve the cohort; off-chain platform-side hardening is the binding intervention. Future contributors should preserve this framing for adjacent off-chain-trust-substrate cases.
- Cross-instance operator-cohort attribution is structurally stronger than per-instance. Independent on-chain forensic linkage (ZachXBT-class) across cohort instances enables stronger attribution than per-instance analysis. Future cohort-attribution work should preserve cross-instance-laundering-cluster-fingerprint as a first-class attribution-strength signal.
- Disguise-memecoin laundering is a Solana-native laundering primitive. The QinShihuang pattern — high-volume disguise-trading through a scam memecoin's pool to launder cross-chain proceeds — is a Solana-specific laundering surface that does not have a clean EVM analogue. Future T7 contributors should record this primitive as a discrete sub-pattern within the broader laundering taxonomy.
- Defender-intervention surface includes audience-side skepticism training. The cohort demonstrates that audience-side skepticism of high-impact X announcements is a real user-layer intervention surface. Future T4-adjacent contributors should preserve this framing as a discrete defender-tooling target distinct from infrastructure-layer hardening.
Public references
[zachxbtpumpfunx2025](proposed) — ZachXBT Telegram thread (republished by Mitrade, Cryptorank, Cryptopolitan): "Hackers compromise Pump.fun X account, issuing fake memecoin announcements"; cross-instance forensic linkage to Jupiter and DogWifCoin: https://www.mitrade.com/insights/news/live-news/article-3-663262-20250227[cryptopolitanpumpfunx2025](proposed) — Cryptopolitan, "ZachXBT: Hackers compromise Pump.fun X account, issuing fake memecoin announcements": https://www.cryptopolitan.com/zachxbt-hackers-compromise-pump-fun-x/[chaindebriefpumpfunx2025](proposed) — Chain Debrief, "Pump.fun X Account Hacked to Promote Fake $PUMP Token": https://pexx.com/chaindebrief/pump-fun-x-account-hacked-to-promote-fake-pump-token/[coinmarketcappumpfunx2025](proposed) — CoinMarketCap Academy, "Pump.fun's X Account Hacked To Promote Fake 'PUMP' Token, Triggering $5 Million Market Cap Surge": https://coinmarketcap.com/academy/article/pumpfuns-x-account-hacked-to-promote-fake-pump-token-triggering-dollar5-million-market-cap-surge[cointelegraphpumpfunx2025](proposed) — Cointelegraph, "Pump.fun X hack reveals security concerns at critical juncture for memecoins": https://cointelegraph.com/news/pump-fun-hack-security-concerns-memecoins[banklesstimesjupiterx2025](proposed) — Bankless Times, "Jupiter's X Account Suffers Hack": https://www.banklesstimes.com/articles/2025/02/06/jupiters-x-account-hacked/[kucoinjupiterx2025](proposed) — KuCoin, "Jupiter DEX X Account Hacked to Promote Scam Memecoins": https://www.kucoin.com/news/articles/jupiter-dex-x-account-hacked-to-promote-scam-memecoins-traders-lose-over-20-million[theblockjupiterx2025](proposed) — The Block, "Solana DEX aggregator Jupiter's X account hacked, promotes fake memecoin": https://www.theblock.co/post/339128/solana-dex-aggregator-jupiters-x-account-hacked-promotes-fake-memecoin[coinspeakerjupiterx2025](proposed) — Coinspeaker, "Crypto Hacks: Jupiter DEX Restores X Account after Hacker Shills Meme Coins": https://www.coinspeaker.com/crypto-hacks-jupiter-dex-restores-x-account-hacker-shills-meme-coins/
Discussion
The Solana brand-X-account-compromise cohort is OAK's canonical 2024-2025 worked example for third-party-platform-substrate compromise producing on-chain crypto-brand losses. The case sits at the intersection of T4 (access acquisition — broadly construed at the social-account-substrate layer), T11.001 (third-party signing-vendor compromise — broadly construed at the platform-administration layer), and T7 (laundering — at the disguise-memecoin sub-pattern).
The structural distinguishing feature of the case is the off-chain-trust-substrate-locus. The cohort's binding defender-intervention surface is X-platform-side (phishing-resistant 2FA enforcement for verified accounts, internal admin-panel access controls), not Solana-protocol-side. This is structurally distinct from the broader DeFi-incident corpus where the binding intervention is on-chain or in protocol-side governance. Future contributors writing off-chain-trust-substrate worked examples should preserve this distinction.
For OAK's broader cohort coverage, this case + the Polymarket Magic-Labs auth-provider cases (examples/2024-09-polymarket-magic-labs-takeover.md) collectively establish that off-chain platform-substrate compromise is now a first-class crypto-brand threat surface with on-chain extraction outcomes. The two cases share the structural shape — third-party platform security ↔ on-chain protocol losses — but differ in the platform substrate (X vs. Magic Labs) and the on-chain extraction primitive (memecoin pump vs. account-takeover-and-drain). Future off-chain-substrate-compromise worked examples should preserve this framing.
The cohort attribution — inferred-strong at cohort scale, unattributed at per-individual operator level — is the canonical 2024-2025 attribution shape for X-account-compromise cohorts. The cross-instance laundering-cluster-fingerprint methodology (ZachXBT's approach) is the v0.x standard; OAK's attribution-strength taxonomy should preserve cohort-scale-cross-instance attribution as a discrete attribution-strength category.
The case also surfaces a v0.x-priority taxonomy gap: the OAK Technique surface at v0.1 lacks a clean slot for brand-account-compromise as a load-bearing crypto-attack vector. T4 covers user-side phishing; T11 covers wallet / signing infrastructure; T6 covers defense evasion; none cleanly captures brand-X-account-compromise. The v0.x development should consider a discrete sub-Technique under T4 or T11 for third-party-communication-channel compromise with the Solana 2024-2025 cohort as the canonical anchor.