On Feb 17,
@pumpfun executed a ResetFeeSharingConfig on
$ChiefPussy (
chiefpussy.com), transferring my admin rights and 75% of creator fees to a third party wallet. Only PumpFun can execute this instruction — it requires their Squads V4 multisig (2-of-25 threshold). At least two PumpFun team members approved it.
PumpFun's explanation: "the original dev wallet owner had applied for a CTO which resulted in them being given Coin Admin privileges."
Here's why the on-chain evidence contradicts this:
- The hacker is not the original dev. The hacker wallet (CFPUAf8nZ978WyRxXihH8sStdgNy7ULGC34QfhTGqQbn) and the original token creator (3H2pYPb9RbnyWgyVRAkNPtvqLc7XPGhzUVUvdSHygj2F) are completely different addresses with zero on-chain interaction. If PumpFun verified the requester was "the original dev," they gave admin to the wrong wallet.
- The hacker wallet was brand new. Its very first SOL came from the stolen fee distribution. They used the stolen 1.58 SOL to trade memecoins, then drained the rest to an exit wallet. This is not a legitimate dev reclaiming their project.
- The attacker knew the fee structure. The 25% shareholder was deliberately preserved in the reset — admin and the 75% recipient were changed, but the 25% share was left untouched.
- The original dev denies involvement. He has publicly stated he never requested a CTO, and has zero on-chain connection to the hacker address.
- The original dev is a great guy, well known in the community. I've known him for only a short time with this coin, and PumpFun's claim feels ridiculous.
- All 5 historical ResetFeeSharingConfig calls on this token went through the same PumpFun multisig. This isn't something anyone outside PumpFun can do. The unauthorized reset was even executed by the same team member who ran a previous legitimate reset on my token.
- PumpFun reversed the change ~9 hours later after I brought this on X, but the hacker had already collected fees. The real concern is the precedent: PumpFun can reassign any token's creator fees without the admin's knowledge or consent.
I'm calling on
@pumpfun to disclose:
1. Who requested the CTO/reset, and what identity verification was performed?
2. What wallet did the requester claim to own?
3. Why was a CTO approved on a token with an active, non-revoked admin?
4. What changes have been made to prevent this from happening again?
Every token creator on PumpFun should be concerned. If it happened to one token, it can happen to any.