OAK — OnChain Attack Knowledge

Worked example · 2025-02

Solana brand-X-account compromise cohort (Jupiter / Pump.fun / DogWifCoin) — Solana — 2024-11 to 2025-02

Loss
aggregate cohort losses across the named X-account-compromise instances are estimated at $20M+ in retail extraction. Per-instance breakdown: Jupiter DEX X account compromise (2025-02-06) — $MEOW scam memecoin promoted; $MEOW briefly exceeded $20M market value before liquidity was drained; KuCoin / Coinspeaker secondary coverage cites "over $20M" in cumulative trader losses across the campaign. Pump.fun X account compromise (2025-02-26 / 2025-02-27) — fake $PUMP "official governance" token promoted; market cap surged to ~$5M during the campaign before the malicious tweets were removed; ZachXBT documented $1.08M USDC received in a single laundering wallet, with subsequent disguise-trading totalling ~$26M traded through the QinShihuang scam memecoin. DogWifCoin ($WIF) X account compromise (2024-11) — predecessor cohort instance; on-chain forensic linkage to the same operator infrastructure per ZachXBT. Cohort-level realised loss to retail traders exceeds the headline-level laundering figures because the scam-memecoin pump-and-dump shape extracts losses across the broader trading-population that bought the fake token before the X account control was restored.
Recovery
none publicly confirmed; the affected X accounts were restored within hours (Jupiter team confirmed regaining account control and that no on-chain protocol funds were compromised); pre-restoration retail losses are not recoverable.
OAK Techniques observed
+ OAK-T15.006 (Impersonation via Verified Social Account Compromise)
Attribution
pseudonymous. ZachXBT (independent on-chain investigator) published forensic threads explicitly linking the Pump.fun, Jupiter, and DogWifCoin X-account compromises on-chain — the same operator infrastructure laundered proceeds across all three campaigns. Per ZachXBT's analysis, the cohort vector is "social engineering [against] employees at X with fraudulent documents/emails or [exploitation of] a panel," consistent with cohort-scale exploitation of X-platform internal-admin surfaces. Jupiter co-founder Meow confirmed that the attack against Jupiter originated from a U.S.-based IP address. The structural fingerprint is consistent with a single operator cohort or a tightly-related cohort cluster across the three named instances, but per-individual operator attribution remains unattributed at v0.1 cutoff. The cohort is structurally distinct from the broader DPRK / OAK-G01 cluster — the operator-tradecraft (X-platform-substrate exploitation, Solana-memecoin-laundering disguise-trading) is commodity-cohort tradecraft rather than long-cycle DPRK operations.
Key teaching point
Brand-X-account control is a load-bearing trust-substrate for crypto-brand communication; its compromise produces direct on-chain extraction without any on-chain protocol vulnerability. The cohort demonstrates that third-party platform security (X-the-platform's internal admin surface) is on-chain-protocol-relevant even when the protocol itself has no security gap. Defender-side intervention surfaces include: (a) X-platform-side hardening (phishing-resistant 2FA enforcement for verified accounts, internal admin-panel access controls), (b) brand-side communication-channel diversification (announcing tokens through multiple channels with cryptographic signing where possible), and (c) audience-side skepticism of high-impact announcements that arrive only via X with no corroborating channels. The cohort generalises across crypto-brand X accounts; Solana-native brands have been particularly exposed in 2024-2025 because the Solana-memecoin substrate provides a fast-extraction substrate that complements the X-amplification surface.
  • OAK-T4 (Access Acquisition — broad construction) at the external-platform-account-compromise sub-surface. The compromise vector targets the Solana-protocol-brand X account (the brand-side communication channel), not the on-chain protocol itself. The on-chain extraction is mediated by the brand's audience trust — followers see legitimate-looking announcements from a trusted source and act on them. Structurally adjacent to T6.002 (Fake Audit Claim) and T4.002 (Compromised Frontend Permit Solicitation) but operating at a different substrate: the social-media-account-substrate rather than the website / DNS / signing-surface substrate.
  • OAK-T11.001 (broad construction) — the X-account-compromise vector is a third-party platform compromise affecting a brand's communication surface. ZachXBT's analysis attributes the compromises to either (a) social-engineering of X employees with fraudulent documents/emails or (b) exploitation of an X internal admin panel. Both vectors implicate X-the-platform's operational security, not the Solana protocols' security. The case is structurally similar to Polymarket's Magic-Labs auth-provider compromises (examples/2024-09-polymarket-magic-labs-takeover.md) in that the trust-substrate is a third-party platform rather than the on-chain protocol — but operates at the audience-amplification layer rather than the user-authentication layer.
  • OAK-T15.005 (Operator-Communication-Channel Takeover) — canonical anchor for the brand-X-account sub-shape at cohort scale. The compromised surface is the operator's public communication channel under the operator's brand; the access was used to distribute malicious-contract-address messages under verified-brand identity, which is the structural signature that maps the cohort primarily to T15.005 rather than to T15.004 (per the T15.005 boundary rule on what-the-access-was-used-for).
  • OAK-T7 (Laundering) chains via the QinShihuang disguise-memecoin pattern — $1.08M USDC received in a laundering wallet was disguised as memecoin trades through a scam token that traded $26M before Solana memecoin platform interventions blocked it. The disguise-trading pattern is a Solana-native laundering-substrate-extension that operates within memecoin-launchpad infrastructure.

Summary

Between November 2024 and February 2025, three high-profile Solana-protocol-brand X (formerly Twitter) accounts were compromised in a connected cohort campaign promoting fake memecoins to large brand-amplified audiences. Per ZachXBT's on-chain forensic analysis, the three named instances are directly connected on-chain — proceeds laundered across all three campaigns flow through overlapping operator infrastructure.

The cohort instances:

  1. DogWifCoin ($WIF) X account compromise — November 2024. The DogWifCoin official X account was compromised; fake announcements promoted scam memecoins. The compromise is the earliest publicly-traceable instance in the connected cohort per ZachXBT's analysis.

  2. Jupiter DEX X account compromise — February 6, 2025. Solana's leading DEX aggregator Jupiter had its main X account hijacked. Hackers promoted fake memecoins $MEOW and $DCOIN; $MEOW briefly surged past $20M market cap before the liquidity was drained, leaving traders unable to sell. JUP token price dropped 12% during the incident; trading volumes on JUP/BTC and JUP/ETH spiked 300%. Jupiter Mobile's separate X handle warned users that "The main Jupiter Exchange account has been compromised" and advised users not to click links. Jupiter regained control within hours and confirmed that no on-chain protocol funds or customer data were compromised. Co-founder Meow stated the attack originated from a U.S.-based IP address. Funds were laundered through BSC wallets before being returned to Solana for further memecoin disguise-trading.

  3. Pump.fun X account compromise — February 26-27, 2025. Solana memecoin launchpad Pump.fun's main X account was compromised. Hackers promoted a fake "official governance" $PUMP token with a Solana contract address, claiming legitimacy. The fake token's market cap surged to ~$5M during the campaign window. Hackers also taunted the community with a follow-up message asking whether they should create a "legit token on Pump.fun" and call it "Hackeddotfun," promising to pump it to a $100M market cap. Pump.fun regained X-account control after several hours and the malicious tweets were removed.

ZachXBT's forensic thread published on Telegram on February 27, 2025, established the on-chain connection across the three cohort instances. Per ZachXBT, $1.08M in USDC flowed into a single operator-cluster wallet from the Pump.fun campaign alone, which was then bridged from BSC to Solana and laundered through the QinShihuang scam memecoin (~$26M cumulative disguise-trading volume) before the Solana memecoin platform intervened to block the token. The same operator-cluster fingerprint appears in the Jupiter and DogWifCoin laundering paths.

The cohort vector — per ZachXBT's analysis — is not a Solana-protocol-side compromise. ZachXBT explicitly states: "[the attacks] are likely not the fault of either the Pump.fun or Jupiter teams." Rather, the attribution-strong vector is X-platform-side exploitation: either social-engineering of X employees with fraudulent documents/emails, or exploitation of an X internal admin-panel surface that allows account-control transfer without the legitimate account holder's authorisation.

The structural shape is therefore: third-party-platform-substrate compromise → brand-amplified-audience deception → Solana-native fast-extraction substrate → cross-chain laundering with disguise-memecoin pattern. The on-chain extraction surface is the Solana-memecoin / Raydium-pool substrate; the trust-substrate-compromise surface is X-platform; the laundering substrate spans Solana / BSC with the QinShihuang disguise-token pattern as a Solana-native laundering primitive.

Why this is structurally significant

The Solana brand-X-account-compromise cohort is structurally distinct from prior crypto-X-account-compromise cases in three ways:

  1. The on-chain-extraction-substrate fit is structurally tight. Crypto X-account compromises predate this cohort (most major exchanges have experienced isolated incidents), but historically the operator-side extraction surface has been relatively narrow — phishing-link distribution, scam-airdrop announcements with limited adoption. The 2024-2025 Solana cohort exploits the Solana-memecoin / Raydium-pool / pump.fun substrate as the extraction primitive, where fake-token deployment is sub-$100, pool-seeding is sub-$1K, and audience-driven price-pump can produce $5-20M market cap within hours. The combination of (a) brand-amplified audience trust, (b) Solana-native fast-deployment economics, and (c) memecoin pump-cycle dynamics produces a structurally-tighter on-chain-extraction fit than prior X-account-compromise cases.

  2. The cross-instance operator-cluster fingerprint is established by independent forensics. ZachXBT's thread explicitly establishes the on-chain linkage across three named instances. The cohort attribution is therefore stronger than per-instance attribution — even where any individual instance might appear to be an isolated incident, the cross-instance laundering-cluster fingerprint demonstrates a sustained operator cohort. This is the canonical 2024-2025 example of cohort-scale X-account-compromise as a discrete attack class, not a sequence of unrelated isolated incidents.

  3. The trust-substrate-locus is X-the-platform's internal admin surface. Per ZachXBT's analysis (and Jupiter co-founder Meow's confirmation that the Jupiter attack originated from a U.S.-based IP), the operator-side leverage was X-platform-side rather than crypto-protocol-side. This is structurally informative: defender-side intervention for the cohort requires X-platform-side hardening (phishing-resistant 2FA enforcement, internal admin-panel access controls), not crypto-protocol-side hardening. The class is therefore a Defender-intervention-surface-not-on-chain Technique class — the on-chain-extraction is real and observable but the binding intervention is at a different substrate. This is structurally adjacent to the Polymarket / Magic Labs auth-provider cases (examples/2024-09-polymarket-magic-labs-takeover.md) where the trust-substrate is also off-chain (auth-provider security, X-platform security) but produces on-chain extraction.

The case generalises beyond Solana to any crypto brand with a high-amplification X account. The 2024-2025 cohort happens to concentrate on Solana brands because (a) Solana's memecoin ecosystem provides the tightest on-chain-extraction-substrate fit and (b) the operator-cluster's Solana-native laundering tradecraft (QinShihuang disguise-trading) is calibrated for the Solana ecosystem. Future X-account-compromise cohorts on other chains will likely produce similar structural shapes adapted to those chains' fast-extraction substrates.

Timeline (UTC)

When Event OAK ref
2024-11 DogWifCoin ($WIF) X account compromised; fake announcements promoting scam memecoins; cohort-precursor instance per ZachXBT's later forensic linkage (cohort genesis surface)
2025-02-06 Jupiter DEX X account compromised; $MEOW and $DCOIN scam memecoins promoted; $MEOW briefly exceeds $20M market cap before liquidity drain; JUP token price drops 12% Cohort instance 2
2025-02-06 Jupiter Mobile X handle warns users; Jupiter regains main account control within hours; co-founder Meow confirms attack originated from U.S.-based IP; no on-chain protocol funds compromised (operator response — Jupiter)
2025-02-06 → days Jupiter post-incident laundering: funds shifted through BSC wallets and back to Solana for further memecoin disguise-trading T7 cross-chain laundering
2025-02-26 / 2025-02-27 Pump.fun X account compromised; fake $PUMP "official governance" token promoted with Solana contract address; market cap surges to ~$5M; community taunted with "Hackeddotfun" follow-up Cohort instance 3
2025-02-27 ZachXBT publishes Telegram thread documenting compromise; explicitly establishes on-chain forensic linkage across Pump.fun, Jupiter, and DogWifCoin instances; attributes vector to X-platform-side social-engineering or admin-panel exploitation Cohort attribution surface
2025-02-27 → days Pump.fun regains X-account control; malicious tweets removed; $1.08M USDC tracked in single laundering wallet; QinShihuang scam memecoin used as disguise-trading vehicle (~$26M cumulative volume before block) T7 disguise-memecoin laundering primitive
2025-02 onward Cointelegraph, CoinMarketCap Academy, Decrypt, KuCoin, Coinspeaker publish secondary coverage; X-account-compromise-cohort framing enters general crypto-press lexicon (forensic + journalism surface)
2025 onward Cohort surface remains active across Solana brand X accounts; isolated additional instances continue across the 2025 calendar year (continuing surface)

What defenders observed

  • Pre-event (X-platform-substrate layer): the X-platform internal admin-panel and customer-support workflow are not directly hardened against social-engineering at the substrate level. Phishing-resistant 2FA enforcement for verified-account-holders is partially implemented but not universally enforced; the internal admin-panel surface is not publicly documented at the granular level required for crypto-brand defender-tooling. Defender lesson: brand-side communication-channel hardening must include diversification to channels that are not single-point-of-failure under X-platform compromise; cryptographically-signed on-chain announcements (e.g., signed messages from a brand-controlled signing address) provide a corroborating channel that compromised X-account messages cannot replicate.
  • At-event (audience-deception layer): the brand-amplified audience treats X-account messages as authoritative. Followers of Jupiter / Pump.fun / DogWifCoin had explicit trust in messages from those accounts; the malicious-message reach was bounded by the account's follower count and engagement patterns, both of which were structurally large for these high-profile brands. Defender lesson: audience-side skepticism of high-impact X announcements (token launches, governance changes, contract-address publications) is the user-side intervention layer; brands should publish explicit security advisories that train users to require multi-channel corroboration for high-impact announcements.
  • At-event (on-chain-extraction layer): the Solana-memecoin / Raydium-pool / pump.fun substrate provided the fast-extraction primitive. Fake $PUMP and $MEOW tokens were deployed and pumped within hours of the X-account-compromise; the realised retail-loss accumulated during the brief account-compromise window. Defender lesson: Solana-side wallet / aggregator UX layers should surface "newly-deployed token from unverified deployer cluster" warnings against tokens that arrive via X-amplified announcements; this is a UX-layer integration with deployer-cluster-attribution analytics.
  • Post-event (laundering-substrate layer): the QinShihuang disguise-memecoin pattern is a Solana-native laundering primitive — proceeds are routed through a scam memecoin's pool to "trade" them through high-volume disguise-pumping before the Solana platform intervenes to block the token. Defender lesson: cross-platform Solana-memecoin coordination (Pump.fun, Raydium, wallet-side blocklists) is the canonical defender-intervention surface for disguise-memecoin laundering; the cohort's persistence demonstrates that platform-side intervention currently lags the operator-side disguise-trading speed.
  • Post-event (cohort-attribution surface): ZachXBT's cross-instance forensic linkage was the load-bearing attribution work. The cohort-scale framing — three instances connected on-chain — is structurally stronger than per-instance framing because it establishes operator-cohort persistence. Defender lesson: independent on-chain investigators (ZachXBT and equivalent) are the dominant cohort-attribution surface for X-account-compromise cohorts; brand-side and platform-side coordination with on-chain forensic researchers should be a first-class defender-tooling priority.

What this example tells contributors writing future Technique pages

  • X-account-compromise is a discrete attack class with on-chain extraction. Future T4 / T11.001-adjacent contributors should preserve the "third-party-platform compromise → brand-amplified-audience deception → fast-extraction-substrate" chain as a discrete sub-class. The Solana 2024-2025 cohort is the canonical worked example.
  • The trust-substrate-locus distinction matters for defender-intervention framing. When the trust-substrate is off-chain (X-platform internal admin surface), on-chain-protocol hardening does not solve the cohort; off-chain platform-side hardening is the binding intervention. Future contributors should preserve this framing for adjacent off-chain-trust-substrate cases.
  • Cross-instance operator-cohort attribution is structurally stronger than per-instance. Independent on-chain forensic linkage (ZachXBT-class) across cohort instances enables stronger attribution than per-instance analysis. Future cohort-attribution work should preserve cross-instance-laundering-cluster-fingerprint as a first-class attribution-strength signal.
  • Disguise-memecoin laundering is a Solana-native laundering primitive. The QinShihuang pattern — high-volume disguise-trading through a scam memecoin's pool to launder cross-chain proceeds — is a Solana-specific laundering surface that does not have a clean EVM analogue. Future T7 contributors should record this primitive as a discrete sub-pattern within the broader laundering taxonomy.
  • Defender-intervention surface includes audience-side skepticism training. The cohort demonstrates that audience-side skepticism of high-impact X announcements is a real user-layer intervention surface. Future T4-adjacent contributors should preserve this framing as a discrete defender-tooling target distinct from infrastructure-layer hardening.

Public references

Discussion

The Solana brand-X-account-compromise cohort is OAK's canonical 2024-2025 worked example for third-party-platform-substrate compromise producing on-chain crypto-brand losses. The case sits at the intersection of T4 (access acquisition — broadly construed at the social-account-substrate layer), T11.001 (third-party signing-vendor compromise — broadly construed at the platform-administration layer), and T7 (laundering — at the disguise-memecoin sub-pattern).

The structural distinguishing feature of the case is the off-chain-trust-substrate-locus. The cohort's binding defender-intervention surface is X-platform-side (phishing-resistant 2FA enforcement for verified accounts, internal admin-panel access controls), not Solana-protocol-side. This is structurally distinct from the broader DeFi-incident corpus where the binding intervention is on-chain or in protocol-side governance. Future contributors writing off-chain-trust-substrate worked examples should preserve this distinction.

For OAK's broader cohort coverage, this case + the Polymarket Magic-Labs auth-provider cases (examples/2024-09-polymarket-magic-labs-takeover.md) collectively establish that off-chain platform-substrate compromise is now a first-class crypto-brand threat surface with on-chain extraction outcomes. The two cases share the structural shape — third-party platform security ↔ on-chain protocol losses — but differ in the platform substrate (X vs. Magic Labs) and the on-chain extraction primitive (memecoin pump vs. account-takeover-and-drain). Future off-chain-substrate-compromise worked examples should preserve this framing.

The cohort attribution — inferred-strong at cohort scale, unattributed at per-individual operator level — is the canonical 2024-2025 attribution shape for X-account-compromise cohorts. The cross-instance laundering-cluster-fingerprint methodology (ZachXBT's approach) is the v0.x standard; OAK's attribution-strength taxonomy should preserve cohort-scale-cross-instance attribution as a discrete attribution-strength category.

The case also surfaces a v0.x-priority taxonomy gap: the OAK Technique surface at v0.1 lacks a clean slot for brand-account-compromise as a load-bearing crypto-attack vector. T4 covers user-side phishing; T11 covers wallet / signing infrastructure; T6 covers defense evasion; none cleanly captures brand-X-account-compromise. The v0.x development should consider a discrete sub-Technique under T4 or T11 for third-party-communication-channel compromise with the Solana 2024-2025 cohort as the canonical anchor.

Techniques demonstrated (5)