TLDR BunniXYZ, an Ethereum-based decentralized exchange, suffered a $2.3M loss due to a smart contract exploit. The hacker targeted the USDT and USDC vaults, draining funds through the Ethereum ecosystem. BunniXYZ’s Liquidity Distribution Function vulnerability allowed the attacker to withdraw more tokens than owned. After the exploit, the hacker swapped stolen funds for ETH and [...] The post BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit appeared first on CoinCentral.TLDR BunniXYZ, an Ethereum-based decentralized exchange, suffered a $2.3M loss due to a smart contract exploit. The hacker targeted the USDT and USDC vaults, draining funds through the Ethereum ecosystem. BunniXYZ’s Liquidity Distribution Function vulnerability allowed the attacker to withdraw more tokens than owned. After the exploit, the hacker swapped stolen funds for ETH and [...] The post BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit appeared first on CoinCentral.

BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit

TLDR

  • BunniXYZ, an Ethereum-based decentralized exchange, suffered a $2.3M loss due to a smart contract exploit.
  • The hacker targeted the USDT and USDC vaults, draining funds through the Ethereum ecosystem.
  • BunniXYZ’s Liquidity Distribution Function vulnerability allowed the attacker to withdraw more tokens than owned.
  • After the exploit, the hacker swapped stolen funds for ETH and moved them through DeFi protocols.
  • BunniXYZ responded quickly by halting all smart contracts to prevent further damage.

BunniXYZ, an Ethereum-based decentralized exchange (DEX), suffered a significant loss of $2.3 million due to a smart contract exploit. The attack targeted the exchange’s liquidity functions, draining mostly stablecoins like USDT and USDC. On-chain investigations confirmed that the hacker exploited a vulnerability in the DEX’s liquidity distribution system.

BunniXYZ’s Smart Contract Vulnerability Exploited

BunniXYZ operates on Ethereum and Unichain, utilizing Uniswap V4 technology. The exchange faced an exploit in one of its smart contracts, allowing the hacker to manipulate liquidity distribution. The hacker targeted USDT and USDC vaults, draining the funds through the Ethereum network.

The vulnerability stemmed from an issue in BunniXYZ’s Liquidity Distribution Function (LDF). This function, which recalculates liquidity, allowed the attacker to withdraw more tokens than they should have. The smart contract’s flaw caused it to miscalculate the liquidity pool, resulting in the loss of funds.

The hacker executed multiple transactions to accumulate $2.3 million before converting the stolen funds to ETH. The attacker then deposited the ETH into Aave, holding a balance of $1.33 million in AethUSDC and $1 million in AethUSDT. BunniXYZ responded promptly by closing all smart contracts to prevent further damage.

Attack Leads to Draining of Stablecoins

The exploit mainly affected stablecoins, with USDT and USDC being the primary targets. The attacker was able to drain these stablecoins by exploiting the flawed recalculation process in BunniXYZ’s smart contract. Once the tokens were extracted, the hacker swapped them for Ethereum and moved the funds through decentralized finance (DeFi) protocols.

In the hour following the attack, the hacker avoided moving or mixing the funds. The initial transaction movements were limited to DeFi swaps, with no immediate effort to obscure the stolen assets. By the time BunniXYZ identified the breach, the hacker had already transferred a substantial portion of the funds.

Despite the relatively small scale of the attack, the breach caused significant damage to the BunniXYZ platform. The DEX was growing rapidly, having reached a peak of $60 million in locked value by the end of August. This breach not only resulted in financial loss but also harmed the platform’s reputation, affecting its future growth prospects.

BunniXYZ Responds to the Exploit

Following the hack, BunniXYZ immediately halted all smart contracts. The response was swift, with the platform seeking to prevent further loss of funds. BunniXYZ had previously undergone audits, but the exploit likely emerged from a new version of its code.

The hack highlights the risks involved in complex liquidity systems within decentralized exchanges. BunniXYZ’s vulnerability may have been a result of a precision bug in the new liquidity recalculation system. As investigations continue, the focus remains on improving security measures to prevent future exploits on platforms like BunniXYZ.

The post BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit appeared first on CoinCentral.

Market Opportunity
Moonveil Logo
Moonveil Price(MORE)
$0.00236
$0.00236$0.00236
+4.65%
USD
Moonveil (MORE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ripple (XRP) Pushes Upwards While One New Crypto Explodes in Popularity

Ripple (XRP) Pushes Upwards While One New Crypto Explodes in Popularity

The post Ripple (XRP) Pushes Upwards While One New Crypto Explodes in Popularity appeared on BitcoinEthereumNews.com. As Ripple (XRP) is slowly recovering through
Share
BitcoinEthereumNews2026/01/18 02:41
Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
Secure the $0.001 Price Before the BlockDAG Presale Ends in 10 Days: Is This the Best Crypto to Buy Today?

Secure the $0.001 Price Before the BlockDAG Presale Ends in 10 Days: Is This the Best Crypto to Buy Today?

Secure your position during the final 12 days of the BlockDAG presale at $0.001 before market forces take over. Learn why this Layer-1 project is seeing massive
Share
CoinLive2026/01/18 02:00