The post Bunni DEX Exploited for $2.3M After Liquidity Rebalancing Flaw appeared on BitcoinEthereumNews.com. Decentralized exchange Bunni fell victim to an exploit, losing about $2.4 million in stablecoins after attackers manipulated the platform’s liquidity calculations, according to onchain data by multiple Web3 security firms. “The Bunni app has been affected by a security exploit,” its team confirmed on X on Tuesday. “As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon,” the team added. The attack targeted Bunni’s Ethereum-based smart contracts. Funds were drained to an address holding $1.33 million in USDC (USDC) and $1.04 million in USDt (USDT). Bunni core contributor @Psaul26ix asked users to withdraw funds from the platform as soon as possible. “If you have money on Bunni, remove it ASAP,” they wrote on X. Bunni channels liquidity through Euler Finance, a decentralized lending platform that enables users to borrow, lend and design structured crypto products. In light of the exploit, Euler co-founder and CEO Michael Bentley clarified that the protocol itself remains unaffected by the exploit. Experts ask Bunni users to remove funds. Source: Michael Bentley Cointelegraph reached out to Bunni and Euler for comment, but had not received a response by publication. Related: Indian court sentences 14 to life in Bitcoin extortion case How Bunni fell victim to the hack While a technical post-mortem remains incomplete, early analysis from developers and researchers points to a flaw in how Bunni handles liquidity rebalancing. Bunni, built on top of Uniswap v4, uses a custom mechanism called Liquidity Distribution Function (LDF) instead of Uniswap’s default logic. This mechanism allows Bunni to optimize liquidity allocation across price ranges, aiming to increase returns for liquidity providers. According to Victor Tran, co-founder of KyberNetwork, the attacker was able to manipulate the LDF curve by executing trades of specific sizes that triggered faulty… The post Bunni DEX Exploited for $2.3M After Liquidity Rebalancing Flaw appeared on BitcoinEthereumNews.com. Decentralized exchange Bunni fell victim to an exploit, losing about $2.4 million in stablecoins after attackers manipulated the platform’s liquidity calculations, according to onchain data by multiple Web3 security firms. “The Bunni app has been affected by a security exploit,” its team confirmed on X on Tuesday. “As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon,” the team added. The attack targeted Bunni’s Ethereum-based smart contracts. Funds were drained to an address holding $1.33 million in USDC (USDC) and $1.04 million in USDt (USDT). Bunni core contributor @Psaul26ix asked users to withdraw funds from the platform as soon as possible. “If you have money on Bunni, remove it ASAP,” they wrote on X. Bunni channels liquidity through Euler Finance, a decentralized lending platform that enables users to borrow, lend and design structured crypto products. In light of the exploit, Euler co-founder and CEO Michael Bentley clarified that the protocol itself remains unaffected by the exploit. Experts ask Bunni users to remove funds. Source: Michael Bentley Cointelegraph reached out to Bunni and Euler for comment, but had not received a response by publication. Related: Indian court sentences 14 to life in Bitcoin extortion case How Bunni fell victim to the hack While a technical post-mortem remains incomplete, early analysis from developers and researchers points to a flaw in how Bunni handles liquidity rebalancing. Bunni, built on top of Uniswap v4, uses a custom mechanism called Liquidity Distribution Function (LDF) instead of Uniswap’s default logic. This mechanism allows Bunni to optimize liquidity allocation across price ranges, aiming to increase returns for liquidity providers. According to Victor Tran, co-founder of KyberNetwork, the attacker was able to manipulate the LDF curve by executing trades of specific sizes that triggered faulty…

Bunni DEX Exploited for $2.3M After Liquidity Rebalancing Flaw

Decentralized exchange Bunni fell victim to an exploit, losing about $2.4 million in stablecoins after attackers manipulated the platform’s liquidity calculations, according to onchain data by multiple Web3 security firms.

“The Bunni app has been affected by a security exploit,” its team confirmed on X on Tuesday. “As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon,” the team added.

The attack targeted Bunni’s Ethereum-based smart contracts. Funds were drained to an address holding $1.33 million in USDC (USDC) and $1.04 million in USDt (USDT).

Bunni core contributor @Psaul26ix asked users to withdraw funds from the platform as soon as possible. “If you have money on Bunni, remove it ASAP,” they wrote on X.

Bunni channels liquidity through Euler Finance, a decentralized lending platform that enables users to borrow, lend and design structured crypto products. In light of the exploit, Euler co-founder and CEO Michael Bentley clarified that the protocol itself remains unaffected by the exploit.

Experts ask Bunni users to remove funds. Source: Michael Bentley

Cointelegraph reached out to Bunni and Euler for comment, but had not received a response by publication.

Related: Indian court sentences 14 to life in Bitcoin extortion case

How Bunni fell victim to the hack

While a technical post-mortem remains incomplete, early analysis from developers and researchers points to a flaw in how Bunni handles liquidity rebalancing.

Bunni, built on top of Uniswap v4, uses a custom mechanism called Liquidity Distribution Function (LDF) instead of Uniswap’s default logic. This mechanism allows Bunni to optimize liquidity allocation across price ranges, aiming to increase returns for liquidity providers.

According to Victor Tran, co-founder of KyberNetwork, the attacker was able to manipulate the LDF curve by executing trades of specific sizes that triggered faulty rebalancing logic.

“Exploiter figured out they could manipulate this LDF by making trades of very specific sizes,” Tran wrote on X. “These carefully chosen amounts caused the rebalancing calculation to break, giving wrong results for how much each LP share should own,” he added.

The attacker appears to have executed the exploit multiple times, gradually draining the protocol’s funds without immediately triggering alarms.

Attacker exploits Bunni’s liquidity function. Source: Victor Tran

As part of their response to the exploit, the Bunni protocol team has offered a 10% bounty to the attacker in exchange for the return of the remaining stolen funds. In an onchain message sent via Ethereum, the team proposed the bounty as a resolution pathway. The message includes a contact address and an email, inviting the attacker to negotiate terms.

Bunni protocol team offers a 10% bounty reward to the hacker. Source: Etherscan

Related: Criminals are ‘vibe hacking’ with AI at unprecedented levels: Anthropic

Crypto hacks top $163 million in August

In August, crypto hackers and scammers stole over $163 million across 16 separate incidents, marking a 15% increase from July’s $142 million. While the figure is still 47% lower year-over-year, it reflects a troubling rise in targeted attacks as crypto markets gain momentum.

PeckShield and other cybersecurity experts noted a strategic shift in hacker behavior, with attackers now focusing on centralized exchanges and high-value individuals, rather than smaller, decentralized targets.

The largest loss in August came from a social engineering attack, where a Bitcoiner was tricked into sending 783 BTC (worth $91 million) to attackers posing as support agents from a crypto exchange and hardware wallet provider.

Magazine: Coinbase hack shows the law probably won’t protect you — Here’s why

Source: https://cointelegraph.com/news/bunni-hack-2-4m-stablecoin-exploit-uniswap-v4?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
USDCoin Logo
USDCoin Price(USDC)
$1,0002
$1,0002$1,0002
0,00%
USD
USDCoin (USDC) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ripple (XRP) Pushes Upwards While One New Crypto Explodes in Popularity

Ripple (XRP) Pushes Upwards While One New Crypto Explodes in Popularity

The post Ripple (XRP) Pushes Upwards While One New Crypto Explodes in Popularity appeared on BitcoinEthereumNews.com. As Ripple (XRP) is slowly recovering through
Share
BitcoinEthereumNews2026/01/18 02:41
Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
Secure the $0.001 Price Before the BlockDAG Presale Ends in 10 Days: Is This the Best Crypto to Buy Today?

Secure the $0.001 Price Before the BlockDAG Presale Ends in 10 Days: Is This the Best Crypto to Buy Today?

Secure your position during the final 12 days of the BlockDAG presale at $0.001 before market forces take over. Learn why this Layer-1 project is seeing massive
Share
CoinLive2026/01/18 02:00