Highlights: Bunni lost $2.3 million in a smart contract exploit attack. The vulnerability came from its Liquidity Distribution Function. The exploiter moved funds to Aave, converting to stablecoins and ETH. Bunni, a decentralized exchange built on Ethereum and Uniswap V4, lost $2.3 million when a security breach let hackers take advantage of a flaw in its liquidity mechanism. The attack happened early on Tuesday, and Certik’s on-chain analysts immediately identified it. The attacker siphoned stablecoins, mostly USDC and USDT, from Bunni’s protocol. These assets were then sent through other decentralized finance (DeFi) platforms and finally deposited into Aave, a well-known lending platform that runs on Ethereum. According to the blockchain data, the wallet of the exploiter held $1.33 million of USDC and $1.04 million of USDT after the exploit. #CertiKInsight We have identified a $2.3M exploit on the @bunni_xyz BunniHub contract.https://t.co/lZB0vzSMQx The exploiter has exfiltrated funds to 0xe04efd87f410e260cf940a3bcb8bc61f33464f2b. Stay Vigilant! — CertiK Alert (@CertiKAlert) September 2, 2025 Liquidity Distribution Function Caused the Smart Contract Exploit At the center of the attack was a weakness in Bunni’s Liquidity Distribution Function (LDF). Bunni’s LDF is different from Uniswap’s default method because it tries to increase returns by moving liquidity around between different price ranges. This method was innovative, but it had a big flaw.  Security researchers exposed the attacker’s approach to exploiting this function, which involved trades of very specific sizes. These trades messed up the LDF’s rebalancing logic, which made a mistake when calculating the value of liquidity provider (LP) shares. This allowed the attacker to receive more tokens than they should have been able to. Victor Tran, the co-founder of KyberNetwork, said that the attacker “figured out they could manipulate the LDF by making trades of very specific sizes.” By doing these exact transactions over and over again, the exploiter was able to slowly take money without setting off any automated alarms. Furthermore, this smart contract exploit revealed a precision bug that could have arisen from a recent update to Bunni’s codebase. Despite the exploit, Bunnie had been audited previously. 1. Bunni is a liquidity hook that runs on top of UniswapV4. Instead of using UniswapV4’s normal system, Bunni has its own liquidity curve called LDF (Liquidity Distribution Function). 2. After each trade, Bunni checks if its LDF curve has changed since the last trade. If it has,… https://t.co/uCSWXyuAt2 — Victor Tran (@vutran54) September 2, 2025 Funds Routed Through Aave Following Exploit After successfully extracting funds from Bunni, the attacker transferred them via several DeFi protocols. Eventually, the stolen assets landed in Aave, which deposited them into lending pools, making tracing and recovery more difficult. Analysts were able to confirm that the attacker’s final wallet held large balances in Aave USDC and USDT assets. Shortly after the exploit was discovered, at 3:04 a.m., Bunni’s team posted a statement on X confirming the breach. The post reads: “The Bunni app has been compromised with a security exploit. For the safety of users, we have paused all smart contract functions on all networks.” Bunni engages with Euler Finance to handle some of its liquidity. However, Euler Labs CEO Michael Bentley explained that their protocol was not impacted by the exploit. He reassured users that none of the Euler systems were compromised during the incident. The timing of the attack was notable. Bunni had just surpassed $60 million in total value locked and more than $1 billion in trading volume in August. Immediately following the attack, BUNNI prices dropped more than 35% within an hour. Further research into the full extent of the exploit is still underway. This incident happened in the midst of a general increase in crypto-related hacks. Over $163 million was lost in 16 crypto-related incidents during the month of August alone. This was a 15% increase from the previous month. eToro Platform Best Crypto Exchange Over 90 top cryptos to trade Regulated by top-tier entities User-friendly trading app 30+ million users 9.9 Visit eToro eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong. Highlights: Bunni lost $2.3 million in a smart contract exploit attack. The vulnerability came from its Liquidity Distribution Function. The exploiter moved funds to Aave, converting to stablecoins and ETH. Bunni, a decentralized exchange built on Ethereum and Uniswap V4, lost $2.3 million when a security breach let hackers take advantage of a flaw in its liquidity mechanism. The attack happened early on Tuesday, and Certik’s on-chain analysts immediately identified it. The attacker siphoned stablecoins, mostly USDC and USDT, from Bunni’s protocol. These assets were then sent through other decentralized finance (DeFi) platforms and finally deposited into Aave, a well-known lending platform that runs on Ethereum. According to the blockchain data, the wallet of the exploiter held $1.33 million of USDC and $1.04 million of USDT after the exploit. #CertiKInsight We have identified a $2.3M exploit on the @bunni_xyz BunniHub contract.https://t.co/lZB0vzSMQx The exploiter has exfiltrated funds to 0xe04efd87f410e260cf940a3bcb8bc61f33464f2b. Stay Vigilant! — CertiK Alert (@CertiKAlert) September 2, 2025 Liquidity Distribution Function Caused the Smart Contract Exploit At the center of the attack was a weakness in Bunni’s Liquidity Distribution Function (LDF). Bunni’s LDF is different from Uniswap’s default method because it tries to increase returns by moving liquidity around between different price ranges. This method was innovative, but it had a big flaw.  Security researchers exposed the attacker’s approach to exploiting this function, which involved trades of very specific sizes. These trades messed up the LDF’s rebalancing logic, which made a mistake when calculating the value of liquidity provider (LP) shares. This allowed the attacker to receive more tokens than they should have been able to. Victor Tran, the co-founder of KyberNetwork, said that the attacker “figured out they could manipulate the LDF by making trades of very specific sizes.” By doing these exact transactions over and over again, the exploiter was able to slowly take money without setting off any automated alarms. Furthermore, this smart contract exploit revealed a precision bug that could have arisen from a recent update to Bunni’s codebase. Despite the exploit, Bunnie had been audited previously. 1. Bunni is a liquidity hook that runs on top of UniswapV4. Instead of using UniswapV4’s normal system, Bunni has its own liquidity curve called LDF (Liquidity Distribution Function). 2. After each trade, Bunni checks if its LDF curve has changed since the last trade. If it has,… https://t.co/uCSWXyuAt2 — Victor Tran (@vutran54) September 2, 2025 Funds Routed Through Aave Following Exploit After successfully extracting funds from Bunni, the attacker transferred them via several DeFi protocols. Eventually, the stolen assets landed in Aave, which deposited them into lending pools, making tracing and recovery more difficult. Analysts were able to confirm that the attacker’s final wallet held large balances in Aave USDC and USDT assets. Shortly after the exploit was discovered, at 3:04 a.m., Bunni’s team posted a statement on X confirming the breach. The post reads: “The Bunni app has been compromised with a security exploit. For the safety of users, we have paused all smart contract functions on all networks.” Bunni engages with Euler Finance to handle some of its liquidity. However, Euler Labs CEO Michael Bentley explained that their protocol was not impacted by the exploit. He reassured users that none of the Euler systems were compromised during the incident. The timing of the attack was notable. Bunni had just surpassed $60 million in total value locked and more than $1 billion in trading volume in August. Immediately following the attack, BUNNI prices dropped more than 35% within an hour. Further research into the full extent of the exploit is still underway. This incident happened in the midst of a general increase in crypto-related hacks. Over $163 million was lost in 16 crypto-related incidents during the month of August alone. This was a 15% increase from the previous month. eToro Platform Best Crypto Exchange Over 90 top cryptos to trade Regulated by top-tier entities User-friendly trading app 30+ million users 9.9 Visit eToro eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Bunni DEX Drained in $2.3M Smart Contract Exploit

2025/09/02 21:09

Highlights:

  • Bunni lost $2.3 million in a smart contract exploit attack.
  • The vulnerability came from its Liquidity Distribution Function.
  • The exploiter moved funds to Aave, converting to stablecoins and ETH.

Bunni, a decentralized exchange built on Ethereum and Uniswap V4, lost $2.3 million when a security breach let hackers take advantage of a flaw in its liquidity mechanism. The attack happened early on Tuesday, and Certik’s on-chain analysts immediately identified it.

The attacker siphoned stablecoins, mostly USDC and USDT, from Bunni’s protocol. These assets were then sent through other decentralized finance (DeFi) platforms and finally deposited into Aave, a well-known lending platform that runs on Ethereum. According to the blockchain data, the wallet of the exploiter held $1.33 million of USDC and $1.04 million of USDT after the exploit.

Liquidity Distribution Function Caused the Smart Contract Exploit

At the center of the attack was a weakness in Bunni’s Liquidity Distribution Function (LDF). Bunni’s LDF is different from Uniswap’s default method because it tries to increase returns by moving liquidity around between different price ranges. This method was innovative, but it had a big flaw. 

Security researchers exposed the attacker’s approach to exploiting this function, which involved trades of very specific sizes. These trades messed up the LDF’s rebalancing logic, which made a mistake when calculating the value of liquidity provider (LP) shares. This allowed the attacker to receive more tokens than they should have been able to.

Victor Tran, the co-founder of KyberNetwork, said that the attacker “figured out they could manipulate the LDF by making trades of very specific sizes.” By doing these exact transactions over and over again, the exploiter was able to slowly take money without setting off any automated alarms. Furthermore, this smart contract exploit revealed a precision bug that could have arisen from a recent update to Bunni’s codebase. Despite the exploit, Bunnie had been audited previously.

Funds Routed Through Aave Following Exploit

After successfully extracting funds from Bunni, the attacker transferred them via several DeFi protocols. Eventually, the stolen assets landed in Aave, which deposited them into lending pools, making tracing and recovery more difficult. Analysts were able to confirm that the attacker’s final wallet held large balances in Aave USDC and USDT assets. Shortly after the exploit was discovered, at 3:04 a.m., Bunni’s team posted a statement on X confirming the breach.

The post reads:

Bunni engages with Euler Finance to handle some of its liquidity. However, Euler Labs CEO Michael Bentley explained that their protocol was not impacted by the exploit. He reassured users that none of the Euler systems were compromised during the incident.

The timing of the attack was notable. Bunni had just surpassed $60 million in total value locked and more than $1 billion in trading volume in August. Immediately following the attack, BUNNI prices dropped more than 35% within an hour. Further research into the full extent of the exploit is still underway. This incident happened in the midst of a general increase in crypto-related hacks. Over $163 million was lost in 16 crypto-related incidents during the month of August alone. This was a 15% increase from the previous month.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Market Opportunity
MemeCore Logo
MemeCore Price(M)
$1.75489
$1.75489$1.75489
+1.57%
USD
MemeCore (M) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP gaat multichain: 5 inzichten uit Ripple’s strategie op Solana Breakpoint

XRP gaat multichain: 5 inzichten uit Ripple’s strategie op Solana Breakpoint

Ripple zet een duidelijke stap richting een bredere rol voor XRP binnen het multichain-ecosysteem. Tijdens het Solana Breakpoint-event lichtte Luke Judges, Global
Share
Coinstats2025/12/16 00:17
Market Direction and Use Case Comparison for 2026 –

Market Direction and Use Case Comparison for 2026 –

The post Market Direction and Use Case Comparison for 2026 – appeared on BitcoinEthereumNews.com. Cryptocurrency markets remain mixed as major assets show varying
Share
BitcoinEthereumNews2025/12/16 00:21
How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Share
BitcoinEthereumNews2025/09/17 23:48