The post Bunni DEX Exploited for $2.3M After Liquidity Rebalancing Flaw appeared on BitcoinEthereumNews.com. Decentralized exchange Bunni fell victim to an exploit, losing about $2.4 million in stablecoins after attackers manipulated the platform’s liquidity calculations, according to onchain data by multiple Web3 security firms. “The Bunni app has been affected by a security exploit,” its team confirmed on X on Tuesday. “As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon,” the team added. The attack targeted Bunni’s Ethereum-based smart contracts. Funds were drained to an address holding $1.33 million in USDC (USDC) and $1.04 million in USDt (USDT). Bunni core contributor @Psaul26ix asked users to withdraw funds from the platform as soon as possible. “If you have money on Bunni, remove it ASAP,” they wrote on X. Bunni channels liquidity through Euler Finance, a decentralized lending platform that enables users to borrow, lend and design structured crypto products. In light of the exploit, Euler co-founder and CEO Michael Bentley clarified that the protocol itself remains unaffected by the exploit. Experts ask Bunni users to remove funds. Source: Michael Bentley Cointelegraph reached out to Bunni and Euler for comment, but had not received a response by publication. Related: Indian court sentences 14 to life in Bitcoin extortion case How Bunni fell victim to the hack While a technical post-mortem remains incomplete, early analysis from developers and researchers points to a flaw in how Bunni handles liquidity rebalancing. Bunni, built on top of Uniswap v4, uses a custom mechanism called Liquidity Distribution Function (LDF) instead of Uniswap’s default logic. This mechanism allows Bunni to optimize liquidity allocation across price ranges, aiming to increase returns for liquidity providers. According to Victor Tran, co-founder of KyberNetwork, the attacker was able to manipulate the LDF curve by executing trades of specific sizes that triggered faulty… The post Bunni DEX Exploited for $2.3M After Liquidity Rebalancing Flaw appeared on BitcoinEthereumNews.com. Decentralized exchange Bunni fell victim to an exploit, losing about $2.4 million in stablecoins after attackers manipulated the platform’s liquidity calculations, according to onchain data by multiple Web3 security firms. “The Bunni app has been affected by a security exploit,” its team confirmed on X on Tuesday. “As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon,” the team added. The attack targeted Bunni’s Ethereum-based smart contracts. Funds were drained to an address holding $1.33 million in USDC (USDC) and $1.04 million in USDt (USDT). Bunni core contributor @Psaul26ix asked users to withdraw funds from the platform as soon as possible. “If you have money on Bunni, remove it ASAP,” they wrote on X. Bunni channels liquidity through Euler Finance, a decentralized lending platform that enables users to borrow, lend and design structured crypto products. In light of the exploit, Euler co-founder and CEO Michael Bentley clarified that the protocol itself remains unaffected by the exploit. Experts ask Bunni users to remove funds. Source: Michael Bentley Cointelegraph reached out to Bunni and Euler for comment, but had not received a response by publication. Related: Indian court sentences 14 to life in Bitcoin extortion case How Bunni fell victim to the hack While a technical post-mortem remains incomplete, early analysis from developers and researchers points to a flaw in how Bunni handles liquidity rebalancing. Bunni, built on top of Uniswap v4, uses a custom mechanism called Liquidity Distribution Function (LDF) instead of Uniswap’s default logic. This mechanism allows Bunni to optimize liquidity allocation across price ranges, aiming to increase returns for liquidity providers. According to Victor Tran, co-founder of KyberNetwork, the attacker was able to manipulate the LDF curve by executing trades of specific sizes that triggered faulty…

Bunni DEX Exploited for $2.3M After Liquidity Rebalancing Flaw

Decentralized exchange Bunni fell victim to an exploit, losing about $2.4 million in stablecoins after attackers manipulated the platform’s liquidity calculations, according to onchain data by multiple Web3 security firms.

“The Bunni app has been affected by a security exploit,” its team confirmed on X on Tuesday. “As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon,” the team added.

The attack targeted Bunni’s Ethereum-based smart contracts. Funds were drained to an address holding $1.33 million in USDC (USDC) and $1.04 million in USDt (USDT).

Bunni core contributor @Psaul26ix asked users to withdraw funds from the platform as soon as possible. “If you have money on Bunni, remove it ASAP,” they wrote on X.

Bunni channels liquidity through Euler Finance, a decentralized lending platform that enables users to borrow, lend and design structured crypto products. In light of the exploit, Euler co-founder and CEO Michael Bentley clarified that the protocol itself remains unaffected by the exploit.

Experts ask Bunni users to remove funds. Source: Michael Bentley

Cointelegraph reached out to Bunni and Euler for comment, but had not received a response by publication.

Related: Indian court sentences 14 to life in Bitcoin extortion case

How Bunni fell victim to the hack

While a technical post-mortem remains incomplete, early analysis from developers and researchers points to a flaw in how Bunni handles liquidity rebalancing.

Bunni, built on top of Uniswap v4, uses a custom mechanism called Liquidity Distribution Function (LDF) instead of Uniswap’s default logic. This mechanism allows Bunni to optimize liquidity allocation across price ranges, aiming to increase returns for liquidity providers.

According to Victor Tran, co-founder of KyberNetwork, the attacker was able to manipulate the LDF curve by executing trades of specific sizes that triggered faulty rebalancing logic.

“Exploiter figured out they could manipulate this LDF by making trades of very specific sizes,” Tran wrote on X. “These carefully chosen amounts caused the rebalancing calculation to break, giving wrong results for how much each LP share should own,” he added.

The attacker appears to have executed the exploit multiple times, gradually draining the protocol’s funds without immediately triggering alarms.

Attacker exploits Bunni’s liquidity function. Source: Victor Tran

As part of their response to the exploit, the Bunni protocol team has offered a 10% bounty to the attacker in exchange for the return of the remaining stolen funds. In an onchain message sent via Ethereum, the team proposed the bounty as a resolution pathway. The message includes a contact address and an email, inviting the attacker to negotiate terms.

Bunni protocol team offers a 10% bounty reward to the hacker. Source: Etherscan

Related: Criminals are ‘vibe hacking’ with AI at unprecedented levels: Anthropic

Crypto hacks top $163 million in August

In August, crypto hackers and scammers stole over $163 million across 16 separate incidents, marking a 15% increase from July’s $142 million. While the figure is still 47% lower year-over-year, it reflects a troubling rise in targeted attacks as crypto markets gain momentum.

PeckShield and other cybersecurity experts noted a strategic shift in hacker behavior, with attackers now focusing on centralized exchanges and high-value individuals, rather than smaller, decentralized targets.

The largest loss in August came from a social engineering attack, where a Bitcoiner was tricked into sending 783 BTC (worth $91 million) to attackers posing as support agents from a crypto exchange and hardware wallet provider.

Magazine: Coinbase hack shows the law probably won’t protect you — Here’s why

Source: https://cointelegraph.com/news/bunni-hack-2-4m-stablecoin-exploit-uniswap-v4?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
USDCoin Logo
USDCoin Price(USDC)
$1.0002
$1.0002$1.0002
0.00%
USD
USDCoin (USDC) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

LMAX Group Deepens Ripple Partnership With RLUSD Collateral Rollout

LMAX Group Deepens Ripple Partnership With RLUSD Collateral Rollout

LMAX Group has revealed a multi-year partnership with Ripple to integrate traditional finance with digital asset markets. As part of the agreement, LMAX will introduce
Share
Tronweekly2026/01/16 23:00
Bitcoin 8% Gains Already Make September 2025 Its Second Best

Bitcoin 8% Gains Already Make September 2025 Its Second Best

The post Bitcoin 8% Gains Already Make September 2025 Its Second Best appeared on BitcoinEthereumNews.com. Key points: Bitcoin is bucking seasonality trends by adding 8%, making this September its best since 2012. September 2025 would need to see 20% upside to become Bitcoin’s strongest ever. BTC price volatility is at levels rarely seen before in an unusual bull cycle. Bitcoin (BTC) has gained more this September than any year since 2012, a new bull market record. Historical price data from CoinGlass and BiTBO confirms that at 8%, Bitcoin’s September 2025 upside is its second-best ever. Bitcoin avoiding “Rektember” with 8% gains September is traditionally Bitcoin’s weakest month, with average losses of around 8%. BTC/USD monthly returns (screenshot). Source: CoinGlass This year, the stakes are high for BTC price seasonality, as historical patterns demand the next bull market peak and other risk assets set repeated new all-time highs. While both gold and the S&P 500 are in price discovery, BTC/USD has coiled throughout September after setting new highs of its own the month prior. Even at “just” 8%, however, this September’s performance is currently enough to make it Bitcoin’s strongest in 13 years. The only time that the ninth month of the year was more profitable for Bitcoin bulls was in 2012, when BTC/USD gained about 19.8%. Last year, upside topped out at 7.3%. BTC/USD monthly returns. Source: BiTBO BTC price volatility vanishes The figures underscore a highly unusual bull market peak year for Bitcoin. Related: BTC ‘pricing in’ what’s coming: 5 things to know in Bitcoin this week Unlike previous bull markets, BTC price volatility has died off in 2025, against the expectations of longtime market participants based on prior performance. CoinGlass data shows volatility dropping to levels not seen in over a decade, with a particularly sharp drop from April onward. Bitcoin historical volatility (screenshot). Source: CoinGlass Onchain analytics firm Glassnode, meanwhile, highlights the…
Share
BitcoinEthereumNews2025/09/18 11:09
Fed rate decision September 2025

Fed rate decision September 2025

The post Fed rate decision September 2025 appeared on BitcoinEthereumNews.com. WASHINGTON – The Federal Reserve on Wednesday approved a widely anticipated rate cut and signaled that two more are on the way before the end of the year as concerns intensified over the U.S. labor market. In an 11-to-1 vote signaling less dissent than Wall Street had anticipated, the Federal Open Market Committee lowered its benchmark overnight lending rate by a quarter percentage point. The decision puts the overnight funds rate in a range between 4.00%-4.25%. Newly-installed Governor Stephen Miran was the only policymaker voting against the quarter-point move, instead advocating for a half-point cut. Governors Michelle Bowman and Christopher Waller, looked at for possible additional dissents, both voted for the 25-basis point reduction. All were appointed by President Donald Trump, who has badgered the Fed all summer to cut not merely in its traditional quarter-point moves but to lower the fed funds rate quickly and aggressively. In the post-meeting statement, the committee again characterized economic activity as having “moderated” but added language saying that “job gains have slowed” and noted that inflation “has moved up and remains somewhat elevated.” Lower job growth and higher inflation are in conflict with the Fed’s twin goals of stable prices and full employment.  “Uncertainty about the economic outlook remains elevated” the Fed statement said. “The Committee is attentive to the risks to both sides of its dual mandate and judges that downside risks to employment have risen.” Markets showed mixed reaction to the developments, with the Dow Jones Industrial Average up more than 300 points but the S&P 500 and Nasdaq Composite posting losses. Treasury yields were modestly lower. At his post-meeting news conference, Fed Chair Jerome Powell echoed the concerns about the labor market. “The marked slowing in both the supply of and demand for workers is unusual in this less dynamic…
Share
BitcoinEthereumNews2025/09/18 02:44