The Bunni protocol, specialized in liquidity management, has temporarily paused the contracts.The Bunni protocol, specialized in liquidity management, has temporarily paused the contracts.

Bunni DEX under attack: approximately $2.4 million in stablecoins stolen on Ethereum, contracts paused

bunni dex hack

A new attack has hit the LP funds on Ethereum: the Bunni protocol, specialized in liquidity management, has temporarily paused the contracts after an anomalous withdrawal estimated between approximately 2.3 and 2.4 million dollars – as reported by The Block and in line with the risks analyzed in the OpenZeppelin Security Report. Initial analyses indicate that the exploit may have exploited a vulnerability in the liquidity distribution function, improperly altering the LP shares.

According to the data collected by our on-chain analysis team, updated as of September 2, 2025, the suspicious transactions show repeated patterns and fractional transfers to multiple addresses, consistent with an attack aimed at exploiting rebalancing. Our cross-checks on public explorers indicate calibrated withdrawals in USDC and USDT for approximately 1.33 million dollars and 1.04 million dollars respectively. Industry analysts note that vulnerabilities related to rebalancing logic and oracles are a recurring cause in recent DeFi incidents.

In brief: what we know so far about the Bunni DEX hack

  • Who: Bunni, liquidity management protocol on Ethereum.
  • What: Draining of funds from smart contracts and operational suspension as a preventive security measure.
  • Dove: Ethereum network, with on-chain traceable movements.
  • When: Event detected in the days leading up to September 2, 2025; investigations are still ongoing.
  • How: Through the manipulation of liquidity rebalancing mechanisms, which led to miscalculations in the LP shares.

Timeline of Events

Essential Sequence

  • Detection of unusual movements in pools with stablecoin, particularly USDC and USDT.
  • Official communication from the team, confirmation of the incident, and suspension of contracts to contain the damage.
  • Preliminary on-chain analysis: estimated losses between approximately 2.3 and 2.4 million dollars, with repeated withdrawals and modulated amounts.
  • Initiation of technical checks on the liquidity distribution function and the rebalancing mechanism.

On-chain Details

  • Affected assets: stablecoin USDC (approximately 1.33 million dollars) and USDT (approximately 1.04 million dollars), which together converge on the estimate of total losses.
  • Pattern: a series of targeted trades with calibrated amounts to force an unfavorable rebalancing for LPs.
  • Addresses and hashes: examined by various blockchain analysis companies, although direct references to explorers have not yet been publicly released.

Various media, including The Block and BitcoinEthereumNews, have reported these elements, highlighting repeated patterns of suspicious transfers in the hours leading up to the suspension of the contracts.

Mechanics of Vulnerability

How Liquidity Distribution Works

Bunni employs a liquidity distribution function that allows capital to be allocated in specific price ranges, optimizing LP returns through transaction-induced rebalancing. The goal is to limit fund inertia; however, this approach can open new attack surfaces if the rebalancing logic is not sufficiently robust. 

Where the System Got Stuck

  • Manipulation of the curve through targeted and repeated trading operations.
  • Calculations of LP positions that, following rebalancing, resulted in incorrect shares.
  • Gradual draining of funds, orchestrated to evade the activation of automatic defensive triggers.

In essence, a non-resilient rebalancing logic allowed attackers to extract value from the LPs without immediately triggering alert mechanisms. An interesting aspect is the modularity of the amounts, indicative of a fine-tuned strategy.

Impact and Numbers

  • Estimated loss: approximately 2.3–2.4 million dollars.
  • Tokens involved: USDC and USDT.
  • Operational status: the contracts have been paused and the smart functions are currently suspended.
  • Critical point: the counting of LP shares and the management of liquidity during rebalancing processes.

Official Reactions and Context

The Bunni team has announced the suspension of contracts as an immediate security measure, clarifying that a post-incident analysis is underway to identify and correct the vulnerability. At the moment, no direct quotes or official statements with verifiable timestamps have been provided; investigations are ongoing and the priority remains securing the contracts and the remaining liquidity. 

Mitigation Measures

  • Ongoing audits on rebalancing functions and LP accounting mechanisms, including tests in adversarial scenarios.
  • Limitation of transaction size that can trigger sensitive rebalancing.
  • Implementation of circuit breaker and real-time monitoring of slippage and abnormal variations in LP quotes.
  • Use of timelock for critical changes and adoption of multisig operations for admin functions.
  • Creation of emergency funds or insurance coverage to mitigate impacts on users.

These countermeasures are essential in DeFi risk management.

Operational Guide for Liquidity Protocols

  • Execution of stress tests and simulations of economic attacks before official releases.
  • Implementation of rate limiting on functions that affect the distribution curve.
  • Active monitoring of alarm metrics such as slippage, changes in LP shares, and unexpected flows to wallets.
  • Periodic update of incident response procedures and drills to validate their effectiveness.
  • Use of reliable oracles and introduction of mathematical guardrails to prevent errors in calculations.

Next Steps for Users and Developers

  • Users: Monitor official protocol updates and check on-chain logs for any changes in the affected pools.
  • Developers: Complete the technical post-mortem, release temporary patches, and plan an independent audit focused on the liquidity management function and LP calculations.

What to Monitor

  • Tx hash and addresses confirmed on explorer like Etherscan or Blockscout for complete traceability.
  • Updates on the release of patches and the expected timeline for the reactivation of contracts.
  • Forensic reports from blockchain analysis companies and public audit results.
  • Any bounty programs or agreements for the return of misappropriated funds.

Conclusions

The attack on Bunni shows how innovations in liquidity distribution can introduce new attack surfaces when the rebalancing mechanism is not robust enough. 

The combination of curve manipulation and errors in LP calculations made it possible to drain approximately 2.3–2.4 million dollars in stablecoins. 

It must be said that the priority now is to complete a transparent post-incident analysis, correct the liquidity management logic, and introduce more rigorous defensive controls.

Numbers and addresses (summary)

  • Estimated amount: approximately 2.3–2.4 million dollars.
  • Token: USDC (approximately 1.33M) and USDT (approximately 1.04M).
  • Status: contracts on hold, investigations ongoing.
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

The post A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release appeared on BitcoinEthereumNews.com. KPop Demon Hunters Netflix Everyone has wondered what may be the next step for KPop Demon Hunters as an IP, given its record-breaking success on Netflix. Now, the answer may be something exactly no one predicted. According to a new filing with the MPA, something called Debut: A KPop Demon Hunters Story has been rated PG by the ratings body. It’s listed alongside some other films, and this is obviously something that has not been publicly announced. A short film could be well, very short, a few minutes, and likely no more than ten. Even that might be pushing it. Using say, Pixar shorts as a reference, most are between 4 and 8 minutes. The original movie is an hour and 36 minutes. The “Debut” in the title indicates some sort of flashback, perhaps to when HUNTR/X first arrived on the scene before they blew up. Previously, director Maggie Kang has commented about how there were more backstory components that were supposed to be in the film that were cut, but hinted those could be explored in a sequel. But perhaps some may be put into a short here. I very much doubt those scenes were fully produced and simply cut, but perhaps they were finished up for this short film here. When would Debut: KPop Demon Hunters theoretically arrive? I’m not sure the other films on the list are much help. Dead of Winter is out in less than two weeks. Mother Mary does not have a release date. Ne Zha 2 came out earlier this year. I’ve only seen news stories saying The Perfect Gamble was supposed to come out in Q1 2025, but I’ve seen no evidence that it actually has. KPop Demon Hunters Netflix It could be sooner rather than later as Netflix looks to capitalize…
Share
BitcoinEthereumNews2025/09/18 02:23
Bitmine Immersion Technologies (BMNR) stock :soars 5% as $13.4B Crypto Treasury Propels Ethereum Supercycle Vision

Bitmine Immersion Technologies (BMNR) stock :soars 5% as $13.4B Crypto Treasury Propels Ethereum Supercycle Vision

TLDR Bitmine surges 5.18% as $13.4B ETH treasury cements crypto dominance. Bitmine’s $12.6B Ethereum trove fuels bold 5% market ownership goal. Bitmine rebounds strong—ETH hoard drives record treasury valuation. Bitmine’s ETH empire grows to 3M coins, powering stock’s sharp rally. With record ETH and cash reserves, Bitmine solidifies crypto supremacy. Bitmine Immersion Technologies closed 5.18% [...] The post Bitmine Immersion Technologies (BMNR) stock :soars 5% as $13.4B Crypto Treasury Propels Ethereum Supercycle Vision appeared first on CoinCentral.
Share
Coincentral2025/10/14 02:40
Headwind Helps Best Wallet Token

Headwind Helps Best Wallet Token

The post Headwind Helps Best Wallet Token appeared on BitcoinEthereumNews.com. Google has announced the launch of a new open-source protocol called Agent Payments Protocol (AP2) in partnership with Coinbase, the Ethereum Foundation, and 60 other organizations. This allows AI agents to make payments on behalf of users using various methods such as real-time bank transfers, credit and debit cards, and, most importantly, stablecoins. Let’s explore in detail what this could mean for the broader cryptocurrency markets, and also highlight a presale crypto (Best Wallet Token) that could explode as a result of this development. Google’s Push for Stablecoins Agent Payments Protocol (AP2) uses digital contracts known as ‘Intent Mandates’ and ‘Verifiable Credentials’ to ensure that AI agents undertake only those payments authorized by the user. Mandates, by the way, are cryptographically signed, tamper-proof digital contracts that act as verifiable proof of a user’s instruction. For example, let’s say you instruct an AI agent to never spend more than $200 in a single transaction. This instruction is written into an Intent Mandate, which serves as a digital contract. Now, whenever the AI agent tries to make a payment, it must present this mandate as proof of authorization, which will then be verified via the AP2 protocol. Alongside this, Google has also launched the A2A x402 extension to accelerate support for the Web3 ecosystem. This production-ready solution enables agent-based crypto payments and will help reshape the growth of cryptocurrency integration within the AP2 protocol. Google’s inclusion of stablecoins in AP2 is a massive vote of confidence in dollar-pegged cryptocurrencies and a huge step toward making them a mainstream payment option. This widens stablecoin usage beyond trading and speculation, positioning them at the center of the consumption economy. The recent enactment of the GENIUS Act in the U.S. gives stablecoins more structure and legal support. Imagine paying for things like data crawls, per-task…
Share
BitcoinEthereumNews2025/09/18 01:27