Skip to content

Bunni DEX Pauses After $2.4M Exploit

Bunni DEX Loses $2.4 Million in Exploit Targeting Liquidity Function

  • Bunni, a decentralized exchange, lost approximately $2.4 million in stablecoins due to a security exploit.
  • The attack manipulated Bunni’s liquidity calculations, draining funds to an address holding $1.33 million in USDC and $1.04 million in USDT.
  • Bunni has paused all smart contract functions and advised users to withdraw their funds immediately.
  • The exploit targeted Bunni’s Ethereum-based smart contracts and was linked to flaws in its Liquidity Distribution Function (LDF).
  • This incident is part of a broader trend, with crypto hacks totaling over $163 million across various incidents in August alone.

The Bunni team confirmed the exploit and is currently investigating the incident while urging users to secure their assets promptly. The manipulation of the LDF curve allowed attackers to execute trades that triggered faulty liquidity rebalancing logic.

As a result of this exploit, Bunni users are facing significant risks, with over $2.4 million lost due to vulnerabilities in the platform’s liquidity management system.(Source)

Share