OAK — OnChain Attack Knowledge

Worked example · 2026-05

Roaring Kitty (@TheRoaringKitty) — verified X-account compromise → $RKC Pump.fun memecoin — 2026-05-11

Loss
~$2.86M extracted by 80+ wallets during the rally (per on-chain analyst StarPlatinum), with the token developer separately accumulating 39.52% of supply via 10 wallets for ~20 SOL (~$1,950) and selling for ~$495K. The Solana memecoin Red Kitten Crew ($RKC) ran from launch to a ~$12.2M market cap in under 30 minutes, then collapsed: roughly $10M+ was wiped from its all-time high after the originating posts were deleted within an hour. The losses fell on retail buyers who rushed in on the apparent endorsement.
OAK Techniques observed
OAK-T15.006 (Impersonation via Verified Social-Account Compromise — the canonical anchor. The verified X account of Keith Gill ("Roaring Kitty"), the GameStop-saga figure with a large dormant following, posted a Pump.fun contract address for $RKC; followers treated the verified, high-profile account as authentic endorsement. See techniques/T15.006-impersonation-via-verified-social-account-compromise.md). OAK-T3.004 (Influencer-Amplified Promotion-and-Dump — the account's reach was the entire attack mechanism: the launch had no product, only the borrowed credibility of a famous account). OAK-T3.001 (Sybil-Bundled Launch — the developer used 10 wallets to accumulate 39.52% of supply for ~$1,950 before the dump, the bundled-supply signature). OAK-T3.003 (Coordinated Pump-and-Dump — the >$12M-cap-in-30-minutes rally and post-deletion collapse).
Attribution
pseudonymous, with a disputed account-control question. The posts appeared from the verified Roaring Kitty account and were deleted within an hour; Keith Gill made no public statement about whether the account was compromised. The on-chain beneficiaries are pseudonymous (the developer's 10-wallet cluster and 80+ rally-extraction wallets are observable on Solana). Whether this was an external account takeover or an authorised-but-deleted post was not publicly resolved — this entry records it as a verified-account-compromise pattern consistent with the contemporaneous Matt Furie and WinRAR verified-X-account compromises, while noting the control question is unconfirmed.
Key teaching point
$RKC is the May-2026 worked example of the dormant-celebrity verified-account weaponisation sub-shape of T15.006 — distinct from the brand-account wave (Solana ecosystem projects, Feb 2025) in that the compromised account belongs to a high-profile individual with a cult following and no recent activity, and the payload is not a drainer link but a freshly-minted memecoin contract that the account's credibility instantly bootstraps to an eight-figure market cap. The financial damage is done entirely through legitimate on-chain actions — real buyers voluntarily buying a real token on Pump.fun — which is why no drainer signature appears: the exploit is the trust transfer from a verified famous account to a worthless token, and the extraction is ordinary selling into the manufactured demand. The detection-signal locus is the social-to-on-chain correlation layer: a dormant verified celebrity account suddenly posting a fresh Pump.fun contract address that mints to a 30-minute eight-figure cap is a high-confidence manufactured-pump signal, regardless of whether the account was hacked.

Summary

On 2026-05-11, the verified X account of Keith Gill ("Roaring Kitty") — the central figure of the 2021 GameStop short-squeeze saga, whose posts have historically moved GME and the broader meme-stock complex — posted a contract address for a Solana-based Pump.fun memecoin called Red Kitten Crew ($RKC), alongside a short cartoon captioned "red bandit crew 4 life." Both posts were deleted within an hour.

In the interval, $RKC went from launch to a ~$12.2M market cap in under 30 minutes as traders rushed in on the apparent Roaring Kitty endorsement. On-chain analyst StarPlatinum reported that more than 80 wallets extracted roughly $2.86M during the rally. Separately, the token developer had pre-positioned: spending 20 SOL ($1,950) across 10 wallets to accumulate 39.52% of total supply before the posts, then selling the holdings for ~$495K. After the posts were deleted, the token collapsed — roughly $10M+ wiped from the all-time high. GameStop (GME) stock briefly surged ~13% on the news before erasing the gain. Keith Gill said nothing publicly about whether his account had been compromised.

The incident sits in a cluster of contemporaneous verified-X-account compromises — reporting at the time asked whether the Roaring Kitty, Matt Furie (Pepe creator), and WinRAR account hacks were connected, suggesting a campaign operating against high-reach verified accounts in mid-May 2026.

Why this is structurally significant

T15.006 (Impersonation via Verified Social-Account Compromise) already has a canonical anchor in the February-2025 Solana brand-account wave (Jupiter, Pump.fun, DogWifCoin), where compromised project accounts pushed drainer links. $RKC is a distinct sub-shape on two axes:

  1. Account type — individual cult-following, not brand. The compromised account belongs to a famous person with a dormant but enormous and emotionally-invested following, not a project with a product. The trust signal is parasocial ("Roaring Kitty is back") rather than institutional ("this is the official Jupiter account"). Dormancy amplifies the effect: a sudden post from a long-quiet legendary account reads as a major event.
  2. Payload — memecoin launch, not drainer. The Feb-2025 wave monetised via on-chain drainers (T4.005 / T4.002): victims signed malicious approvals. $RKC monetises via an ordinary market: victims buy a token. No malicious signature, no approval, no drainer contract — just a fresh Pump.fun mint that the borrowed credibility floats to $12M. This makes the on-chain forensics cleaner-looking (every buy is voluntary and legitimate) and the harm harder to frame as a "hack" of the buyers — yet the loss is real and the mechanism is the compromised verified account.

The case also shows the pre-positioned-developer + amplification-event composition. The 10-wallet, 39.52%-supply accumulation for ~$1,950 is a textbook Sybil-bundled launch (T3.001): the developer controlled a supermajority of float at near-zero cost before the amplification event, guaranteeing that the manufactured demand would flow into their bags. Whoever controlled the posting and whoever controlled the developer wallets need not be the same party — but the bundled pre-position is what converts a 30-minute pump into a $495K developer realisation. Contributors should record the bundle-then-amplify sequence as the structural core, with the verified-account post as the amplification trigger.

Finally, the GME spillover (a ~13% equity move) marks this as a rare on-chain event with a measurable traditional-market footprint, underscoring that verified-account compromises of figures who straddle TradFi and crypto have cross-market blast radius.

Timeline (UTC)

When Event OAK ref
Pre-2026-05-11 Token developer spends 20 SOL ($1,950) across 10 wallets to accumulate 39.52% of $RKC supply ahead of any public attention T3.001 (Sybil-bundled supply pre-position)
2026-05-11 Verified Roaring Kitty (@TheRoaringKitty) X account posts a Pump.fun contract address for Red Kitten Crew ($RKC) and a "red bandit crew 4 life" cartoon T15.006 (verified-account post), T3.004 (influencer amplification)
2026-05-11 (<30 min) $RKC rallies from launch to ~$12.2M market cap; 80+ wallets extract ~$2.86M during the rally T3.003 (pump), T5 outflow
2026-05-11 (<1h) Both posts deleted within an hour; token collapses, ~$10M+ wiped from ATH; developer sells the 39.52% stake for ~$495K T3.003 (dump), T5.006-adjacent (insider realisation)
2026-05-11 GME stock briefly surges ~13% then erases the gain; Keith Gill makes no public statement on account compromise (cross-market spillover / disclosure gap)
Mid-2026-05 Reporting links the Roaring Kitty, Matt Furie, and WinRAR verified-X-account compromises as a possible coordinated campaign (campaign-correlation signal)

What defenders observed

  • Pre-event (on-chain pre-position signal): a 10-wallet cluster accumulated 39.52% of a token's supply for ~$1,950 before any public catalyst. A bundled-launch detector (single-funder cluster acquiring a supermajority of a fresh mint's float) would have flagged the pre-position independently of the social event. This is the highest-confidence, earliest signal.
  • At-event (social-to-on-chain correlation): a dormant verified celebrity account posted a fresh Pump.fun contract address that minted to a $12.2M cap in under 30 minutes. The conjunction — verified high-reach account + brand-new contract + vertical price action — is a manufactured-pump signature whether or not the account was compromised. Wallet-security and exchange-listing surfaces should treat a contract address first surfaced by a suddenly-active dormant celebrity account as elevated-risk by default.
  • At-event (deletion signal): the originating posts were deleted within an hour — consistent with either a compromise being remediated or an authorised post being walked back. Either way, post deletion shortly after an eight-figure pump is itself a flag that the catalyst was illegitimate.
  • Post-event (extraction pattern): 80+ wallets realised ~$2.86M into the rally and the developer realised ~$495K from the pre-positioned 39.52%. The extraction is ordinary selling, not draining — no malicious approvals appear — which is exactly why the loss must be attributed to the trust-transfer mechanism (the verified-account post) rather than to any on-chain exploit primitive.

What this example tells contributors writing future Technique pages

  • T15.006 needs a dormant-celebrity-individual sub-shape distinct from the brand-account wave. The trust signal (parasocial, amplified by dormancy) and the payload (memecoin launch, not drainer) both differ. The detection guidance — correlate sudden dormant-celebrity activity with fresh-contract mints — is specific to this sub-shape.
  • "No drainer, still a T15.006 loss" is the instructive framing. When the monetisation is voluntary buying into a manufactured pump rather than a malicious signature, the on-chain forensics look clean and the harm resists the "hack" label. The taxonomy should be explicit that verified-account compromise can monetise through an ordinary market and that the absence of a drainer signature does not move the case out of T15.006.
  • Record bundle-then-amplify as a composition. T3.001 (bundled pre-position) + T15.006/T3.004 (amplification trigger) is a recurring memecoin-attack template; the bundle is the pre-positioned profit mechanism and the verified-account post is the trigger. They may be operated by different parties.
  • Cross-market spillover is a recordable T15.006 impact dimension for figures who straddle TradFi and crypto (the GME move). Most T15.006 cases are crypto-internal; this one was not.

Public references

Discussion

$RKC extends the T15.006 reference set from the brand-account wave (Solana ecosystem projects, Feb 2025, drainer payload) to the dormant-celebrity-individual sub-shape: a famous person's quiet, verified, emotionally-loaded account, reactivated to push a fresh memecoin rather than a phishing link. The shift in payload — from drainer to ordinary memecoin launch — is the analytically important part: it produces a loss with no malicious on-chain signature, because the victims' losing trades are voluntary purchases. The harm is entirely in the trust transfer from the verified famous account to a worthless token, which is precisely what T15.006 is meant to capture.

The case pairs with the corpus's bundled-launch and influencer-amplified-rug material (T3.001 / T3.004, and the 2021-2026-influencer-amplified-non-memecoin-rug-cohort.md lineage): the developer's 10-wallet, 39.52%-supply, ~$1,950 pre-position is the bundled profit mechanism, and the verified-account post is the amplification trigger that floats it to $12M. The contemporaneous Matt Furie and WinRAR verified-account compromises suggest a mid-May-2026 campaign against high-reach verified accounts; whether the parties controlling the posts, the developer wallets, and the campaign overlap is unresolved, and Keith Gill's public silence on whether his account was compromised leaves the control question formally open — which is itself the recurring evidentiary problem with celebrity-account memecoin events.

Techniques demonstrated (4)