TLDR BunniXYZ, an Ethereum-based decentralized exchange, suffered a $2.3M loss due to a smart contract exploit. The hacker targeted the USDT and USDC vaults, draining funds through the Ethereum ecosystem. BunniXYZ’s Liquidity Distribution Function vulnerability allowed the attacker to withdraw more tokens than owned. After the exploit, the hacker swapped stolen funds for ETH and [...] The post BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit appeared first on CoinCentral.TLDR BunniXYZ, an Ethereum-based decentralized exchange, suffered a $2.3M loss due to a smart contract exploit. The hacker targeted the USDT and USDC vaults, draining funds through the Ethereum ecosystem. BunniXYZ’s Liquidity Distribution Function vulnerability allowed the attacker to withdraw more tokens than owned. After the exploit, the hacker swapped stolen funds for ETH and [...] The post BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit appeared first on CoinCentral.

BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit

2025/09/02 22:57
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

TLDR

  • BunniXYZ, an Ethereum-based decentralized exchange, suffered a $2.3M loss due to a smart contract exploit.
  • The hacker targeted the USDT and USDC vaults, draining funds through the Ethereum ecosystem.
  • BunniXYZ’s Liquidity Distribution Function vulnerability allowed the attacker to withdraw more tokens than owned.
  • After the exploit, the hacker swapped stolen funds for ETH and moved them through DeFi protocols.
  • BunniXYZ responded quickly by halting all smart contracts to prevent further damage.

BunniXYZ, an Ethereum-based decentralized exchange (DEX), suffered a significant loss of $2.3 million due to a smart contract exploit. The attack targeted the exchange’s liquidity functions, draining mostly stablecoins like USDT and USDC. On-chain investigations confirmed that the hacker exploited a vulnerability in the DEX’s liquidity distribution system.

BunniXYZ’s Smart Contract Vulnerability Exploited

BunniXYZ operates on Ethereum and Unichain, utilizing Uniswap V4 technology. The exchange faced an exploit in one of its smart contracts, allowing the hacker to manipulate liquidity distribution. The hacker targeted USDT and USDC vaults, draining the funds through the Ethereum network.

The vulnerability stemmed from an issue in BunniXYZ’s Liquidity Distribution Function (LDF). This function, which recalculates liquidity, allowed the attacker to withdraw more tokens than they should have. The smart contract’s flaw caused it to miscalculate the liquidity pool, resulting in the loss of funds.

The hacker executed multiple transactions to accumulate $2.3 million before converting the stolen funds to ETH. The attacker then deposited the ETH into Aave, holding a balance of $1.33 million in AethUSDC and $1 million in AethUSDT. BunniXYZ responded promptly by closing all smart contracts to prevent further damage.

Attack Leads to Draining of Stablecoins

The exploit mainly affected stablecoins, with USDT and USDC being the primary targets. The attacker was able to drain these stablecoins by exploiting the flawed recalculation process in BunniXYZ’s smart contract. Once the tokens were extracted, the hacker swapped them for Ethereum and moved the funds through decentralized finance (DeFi) protocols.

In the hour following the attack, the hacker avoided moving or mixing the funds. The initial transaction movements were limited to DeFi swaps, with no immediate effort to obscure the stolen assets. By the time BunniXYZ identified the breach, the hacker had already transferred a substantial portion of the funds.

Despite the relatively small scale of the attack, the breach caused significant damage to the BunniXYZ platform. The DEX was growing rapidly, having reached a peak of $60 million in locked value by the end of August. This breach not only resulted in financial loss but also harmed the platform’s reputation, affecting its future growth prospects.

BunniXYZ Responds to the Exploit

Following the hack, BunniXYZ immediately halted all smart contracts. The response was swift, with the platform seeking to prevent further loss of funds. BunniXYZ had previously undergone audits, but the exploit likely emerged from a new version of its code.

The hack highlights the risks involved in complex liquidity systems within decentralized exchanges. BunniXYZ’s vulnerability may have been a result of a precision bug in the new liquidity recalculation system. As investigations continue, the focus remains on improving security measures to prevent future exploits on platforms like BunniXYZ.

The post BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit appeared first on CoinCentral.

시장 기회
Moonveil 로고
Moonveil 가격(MORE)
$0.00003953
$0.00003953$0.00003953
+4.65%
USD
Moonveil (MORE) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!