The post Bunni DEX Exploited for $2.3M After Liquidity Rebalancing Flaw appeared on BitcoinEthereumNews.com. Decentralized exchange Bunni fell victim to an exploit, losing about $2.4 million in stablecoins after attackers manipulated the platform’s liquidity calculations, according to onchain data by multiple Web3 security firms. “The Bunni app has been affected by a security exploit,” its team confirmed on X on Tuesday. “As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon,” the team added. The attack targeted Bunni’s Ethereum-based smart contracts. Funds were drained to an address holding $1.33 million in USDC (USDC) and $1.04 million in USDt (USDT). Bunni core contributor @Psaul26ix asked users to withdraw funds from the platform as soon as possible. “If you have money on Bunni, remove it ASAP,” they wrote on X. Bunni channels liquidity through Euler Finance, a decentralized lending platform that enables users to borrow, lend and design structured crypto products. In light of the exploit, Euler co-founder and CEO Michael Bentley clarified that the protocol itself remains unaffected by the exploit. Experts ask Bunni users to remove funds. Source: Michael Bentley Cointelegraph reached out to Bunni and Euler for comment, but had not received a response by publication. Related: Indian court sentences 14 to life in Bitcoin extortion case How Bunni fell victim to the hack While a technical post-mortem remains incomplete, early analysis from developers and researchers points to a flaw in how Bunni handles liquidity rebalancing. Bunni, built on top of Uniswap v4, uses a custom mechanism called Liquidity Distribution Function (LDF) instead of Uniswap’s default logic. This mechanism allows Bunni to optimize liquidity allocation across price ranges, aiming to increase returns for liquidity providers. According to Victor Tran, co-founder of KyberNetwork, the attacker was able to manipulate the LDF curve by executing trades of specific sizes that triggered faulty… The post Bunni DEX Exploited for $2.3M After Liquidity Rebalancing Flaw appeared on BitcoinEthereumNews.com. Decentralized exchange Bunni fell victim to an exploit, losing about $2.4 million in stablecoins after attackers manipulated the platform’s liquidity calculations, according to onchain data by multiple Web3 security firms. “The Bunni app has been affected by a security exploit,” its team confirmed on X on Tuesday. “As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon,” the team added. The attack targeted Bunni’s Ethereum-based smart contracts. Funds were drained to an address holding $1.33 million in USDC (USDC) and $1.04 million in USDt (USDT). Bunni core contributor @Psaul26ix asked users to withdraw funds from the platform as soon as possible. “If you have money on Bunni, remove it ASAP,” they wrote on X. Bunni channels liquidity through Euler Finance, a decentralized lending platform that enables users to borrow, lend and design structured crypto products. In light of the exploit, Euler co-founder and CEO Michael Bentley clarified that the protocol itself remains unaffected by the exploit. Experts ask Bunni users to remove funds. Source: Michael Bentley Cointelegraph reached out to Bunni and Euler for comment, but had not received a response by publication. Related: Indian court sentences 14 to life in Bitcoin extortion case How Bunni fell victim to the hack While a technical post-mortem remains incomplete, early analysis from developers and researchers points to a flaw in how Bunni handles liquidity rebalancing. Bunni, built on top of Uniswap v4, uses a custom mechanism called Liquidity Distribution Function (LDF) instead of Uniswap’s default logic. This mechanism allows Bunni to optimize liquidity allocation across price ranges, aiming to increase returns for liquidity providers. According to Victor Tran, co-founder of KyberNetwork, the attacker was able to manipulate the LDF curve by executing trades of specific sizes that triggered faulty…

Bunni DEX Exploited for $2.3M After Liquidity Rebalancing Flaw

3 min read

Decentralized exchange Bunni fell victim to an exploit, losing about $2.4 million in stablecoins after attackers manipulated the platform’s liquidity calculations, according to onchain data by multiple Web3 security firms.

“The Bunni app has been affected by a security exploit,” its team confirmed on X on Tuesday. “As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon,” the team added.

The attack targeted Bunni’s Ethereum-based smart contracts. Funds were drained to an address holding $1.33 million in USDC (USDC) and $1.04 million in USDt (USDT).

Bunni core contributor @Psaul26ix asked users to withdraw funds from the platform as soon as possible. “If you have money on Bunni, remove it ASAP,” they wrote on X.

Bunni channels liquidity through Euler Finance, a decentralized lending platform that enables users to borrow, lend and design structured crypto products. In light of the exploit, Euler co-founder and CEO Michael Bentley clarified that the protocol itself remains unaffected by the exploit.

Experts ask Bunni users to remove funds. Source: Michael Bentley

Cointelegraph reached out to Bunni and Euler for comment, but had not received a response by publication.

Related: Indian court sentences 14 to life in Bitcoin extortion case

How Bunni fell victim to the hack

While a technical post-mortem remains incomplete, early analysis from developers and researchers points to a flaw in how Bunni handles liquidity rebalancing.

Bunni, built on top of Uniswap v4, uses a custom mechanism called Liquidity Distribution Function (LDF) instead of Uniswap’s default logic. This mechanism allows Bunni to optimize liquidity allocation across price ranges, aiming to increase returns for liquidity providers.

According to Victor Tran, co-founder of KyberNetwork, the attacker was able to manipulate the LDF curve by executing trades of specific sizes that triggered faulty rebalancing logic.

“Exploiter figured out they could manipulate this LDF by making trades of very specific sizes,” Tran wrote on X. “These carefully chosen amounts caused the rebalancing calculation to break, giving wrong results for how much each LP share should own,” he added.

The attacker appears to have executed the exploit multiple times, gradually draining the protocol’s funds without immediately triggering alarms.

Attacker exploits Bunni’s liquidity function. Source: Victor Tran

As part of their response to the exploit, the Bunni protocol team has offered a 10% bounty to the attacker in exchange for the return of the remaining stolen funds. In an onchain message sent via Ethereum, the team proposed the bounty as a resolution pathway. The message includes a contact address and an email, inviting the attacker to negotiate terms.

Bunni protocol team offers a 10% bounty reward to the hacker. Source: Etherscan

Related: Criminals are ‘vibe hacking’ with AI at unprecedented levels: Anthropic

Crypto hacks top $163 million in August

In August, crypto hackers and scammers stole over $163 million across 16 separate incidents, marking a 15% increase from July’s $142 million. While the figure is still 47% lower year-over-year, it reflects a troubling rise in targeted attacks as crypto markets gain momentum.

PeckShield and other cybersecurity experts noted a strategic shift in hacker behavior, with attackers now focusing on centralized exchanges and high-value individuals, rather than smaller, decentralized targets.

The largest loss in August came from a social engineering attack, where a Bitcoiner was tricked into sending 783 BTC (worth $91 million) to attackers posing as support agents from a crypto exchange and hardware wallet provider.

Magazine: Coinbase hack shows the law probably won’t protect you — Here’s why

Source: https://cointelegraph.com/news/bunni-hack-2-4m-stablecoin-exploit-uniswap-v4?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
USDCoin Logo
USDCoin Price(USDC)
$1.001
$1.001$1.001
-0.03%
USD
USDCoin (USDC) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

The post Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now? appeared on BitcoinEthereumNews.com. On the lookout for a Sector – Tech fund? Starting with Putnam Global Technology A (PGTAX – Free Report) should not be a possibility at this time. PGTAX possesses a Zacks Mutual Fund Rank of 4 (Sell), which is based on various forecasting factors like size, cost, and past performance. Objective We note that PGTAX is a Sector – Tech option, and this area is loaded with many options. Found in a wide number of industries such as semiconductors, software, internet, and networking, tech companies are everywhere. Thus, Sector – Tech mutual funds that invest in technology let investors own a stake in a notoriously volatile sector, but with a much more diversified approach. History of fund/manager Putnam Funds is based in Canton, MA, and is the manager of PGTAX. The Putnam Global Technology A made its debut in January of 2009 and PGTAX has managed to accumulate roughly $650.01 million in assets, as of the most recently available information. The fund is currently managed by Di Yao who has been in charge of the fund since December of 2012. Performance Obviously, what investors are looking for in these funds is strong performance relative to their peers. PGTAX has a 5-year annualized total return of 14.46%, and is in the middle third among its category peers. But if you are looking for a shorter time frame, it is also worth looking at its 3-year annualized total return of 27.02%, which places it in the middle third during this time-frame. It is important to note that the product’s returns may not reflect all its expenses. Any fees not reflected would lower the returns. Total returns do not reflect the fund’s [%] sale charge. If sales charges were included, total returns would have been lower. When looking at a fund’s performance, it…
Share
BitcoinEthereumNews2025/09/18 04:05
“Vibes Should Match Substance”: Vitalik on Fake Ethereum Connections

“Vibes Should Match Substance”: Vitalik on Fake Ethereum Connections

Vitalik Buterin criticized L2s that use optimistic bridges without adding meaningful technical innovation. Ethereum’s base layer is scaling, reducing the need for
Share
LiveBitcoinNews2026/02/06 11:30
Why Bitcoin Crashed Below $69,000 — Causes & Outlook

Why Bitcoin Crashed Below $69,000 — Causes & Outlook

Cryptsy - Latest Cryptocurrency News and Predictions Cryptsy - Latest Cryptocurrency News and Predictions - Experts in Crypto Casinos Bitcoin crash explained:
Share
Cryptsy2026/02/06 11:20