TLDR BunniXYZ, an Ethereum-based decentralized exchange, suffered a $2.3M loss due to a smart contract exploit. The hacker targeted the USDT and USDC vaults, draining funds through the Ethereum ecosystem. BunniXYZ’s Liquidity Distribution Function vulnerability allowed the attacker to withdraw more tokens than owned. After the exploit, the hacker swapped stolen funds for ETH and [...] The post BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit appeared first on CoinCentral.TLDR BunniXYZ, an Ethereum-based decentralized exchange, suffered a $2.3M loss due to a smart contract exploit. The hacker targeted the USDT and USDC vaults, draining funds through the Ethereum ecosystem. BunniXYZ’s Liquidity Distribution Function vulnerability allowed the attacker to withdraw more tokens than owned. After the exploit, the hacker swapped stolen funds for ETH and [...] The post BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit appeared first on CoinCentral.

BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit

TLDR

  • BunniXYZ, an Ethereum-based decentralized exchange, suffered a $2.3M loss due to a smart contract exploit.
  • The hacker targeted the USDT and USDC vaults, draining funds through the Ethereum ecosystem.
  • BunniXYZ’s Liquidity Distribution Function vulnerability allowed the attacker to withdraw more tokens than owned.
  • After the exploit, the hacker swapped stolen funds for ETH and moved them through DeFi protocols.
  • BunniXYZ responded quickly by halting all smart contracts to prevent further damage.

BunniXYZ, an Ethereum-based decentralized exchange (DEX), suffered a significant loss of $2.3 million due to a smart contract exploit. The attack targeted the exchange’s liquidity functions, draining mostly stablecoins like USDT and USDC. On-chain investigations confirmed that the hacker exploited a vulnerability in the DEX’s liquidity distribution system.

BunniXYZ’s Smart Contract Vulnerability Exploited

BunniXYZ operates on Ethereum and Unichain, utilizing Uniswap V4 technology. The exchange faced an exploit in one of its smart contracts, allowing the hacker to manipulate liquidity distribution. The hacker targeted USDT and USDC vaults, draining the funds through the Ethereum network.

The vulnerability stemmed from an issue in BunniXYZ’s Liquidity Distribution Function (LDF). This function, which recalculates liquidity, allowed the attacker to withdraw more tokens than they should have. The smart contract’s flaw caused it to miscalculate the liquidity pool, resulting in the loss of funds.

The hacker executed multiple transactions to accumulate $2.3 million before converting the stolen funds to ETH. The attacker then deposited the ETH into Aave, holding a balance of $1.33 million in AethUSDC and $1 million in AethUSDT. BunniXYZ responded promptly by closing all smart contracts to prevent further damage.

Attack Leads to Draining of Stablecoins

The exploit mainly affected stablecoins, with USDT and USDC being the primary targets. The attacker was able to drain these stablecoins by exploiting the flawed recalculation process in BunniXYZ’s smart contract. Once the tokens were extracted, the hacker swapped them for Ethereum and moved the funds through decentralized finance (DeFi) protocols.

In the hour following the attack, the hacker avoided moving or mixing the funds. The initial transaction movements were limited to DeFi swaps, with no immediate effort to obscure the stolen assets. By the time BunniXYZ identified the breach, the hacker had already transferred a substantial portion of the funds.

Despite the relatively small scale of the attack, the breach caused significant damage to the BunniXYZ platform. The DEX was growing rapidly, having reached a peak of $60 million in locked value by the end of August. This breach not only resulted in financial loss but also harmed the platform’s reputation, affecting its future growth prospects.

BunniXYZ Responds to the Exploit

Following the hack, BunniXYZ immediately halted all smart contracts. The response was swift, with the platform seeking to prevent further loss of funds. BunniXYZ had previously undergone audits, but the exploit likely emerged from a new version of its code.

The hack highlights the risks involved in complex liquidity systems within decentralized exchanges. BunniXYZ’s vulnerability may have been a result of a precision bug in the new liquidity recalculation system. As investigations continue, the focus remains on improving security measures to prevent future exploits on platforms like BunniXYZ.

The post BunniXYZ Ethereum Exchange Loses $2.3M in Smart Contract Exploit appeared first on CoinCentral.

Market Opportunity
Moonveil Logo
Moonveil Price(MORE)
$0.002193
$0.002193$0.002193
+1.24%
USD
Moonveil (MORE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

LMAX Group Deepens Ripple Partnership With RLUSD Collateral Rollout

LMAX Group Deepens Ripple Partnership With RLUSD Collateral Rollout

LMAX Group has revealed a multi-year partnership with Ripple to integrate traditional finance with digital asset markets. As part of the agreement, LMAX will introduce
Share
Tronweekly2026/01/16 23:00
Bitcoin 8% Gains Already Make September 2025 Its Second Best

Bitcoin 8% Gains Already Make September 2025 Its Second Best

The post Bitcoin 8% Gains Already Make September 2025 Its Second Best appeared on BitcoinEthereumNews.com. Key points: Bitcoin is bucking seasonality trends by adding 8%, making this September its best since 2012. September 2025 would need to see 20% upside to become Bitcoin’s strongest ever. BTC price volatility is at levels rarely seen before in an unusual bull cycle. Bitcoin (BTC) has gained more this September than any year since 2012, a new bull market record. Historical price data from CoinGlass and BiTBO confirms that at 8%, Bitcoin’s September 2025 upside is its second-best ever. Bitcoin avoiding “Rektember” with 8% gains September is traditionally Bitcoin’s weakest month, with average losses of around 8%. BTC/USD monthly returns (screenshot). Source: CoinGlass This year, the stakes are high for BTC price seasonality, as historical patterns demand the next bull market peak and other risk assets set repeated new all-time highs. While both gold and the S&P 500 are in price discovery, BTC/USD has coiled throughout September after setting new highs of its own the month prior. Even at “just” 8%, however, this September’s performance is currently enough to make it Bitcoin’s strongest in 13 years. The only time that the ninth month of the year was more profitable for Bitcoin bulls was in 2012, when BTC/USD gained about 19.8%. Last year, upside topped out at 7.3%. BTC/USD monthly returns. Source: BiTBO BTC price volatility vanishes The figures underscore a highly unusual bull market peak year for Bitcoin. Related: BTC ‘pricing in’ what’s coming: 5 things to know in Bitcoin this week Unlike previous bull markets, BTC price volatility has died off in 2025, against the expectations of longtime market participants based on prior performance. CoinGlass data shows volatility dropping to levels not seen in over a decade, with a particularly sharp drop from April onward. Bitcoin historical volatility (screenshot). Source: CoinGlass Onchain analytics firm Glassnode, meanwhile, highlights the…
Share
BitcoinEthereumNews2025/09/18 11:09
Fed rate decision September 2025

Fed rate decision September 2025

The post Fed rate decision September 2025 appeared on BitcoinEthereumNews.com. WASHINGTON – The Federal Reserve on Wednesday approved a widely anticipated rate cut and signaled that two more are on the way before the end of the year as concerns intensified over the U.S. labor market. In an 11-to-1 vote signaling less dissent than Wall Street had anticipated, the Federal Open Market Committee lowered its benchmark overnight lending rate by a quarter percentage point. The decision puts the overnight funds rate in a range between 4.00%-4.25%. Newly-installed Governor Stephen Miran was the only policymaker voting against the quarter-point move, instead advocating for a half-point cut. Governors Michelle Bowman and Christopher Waller, looked at for possible additional dissents, both voted for the 25-basis point reduction. All were appointed by President Donald Trump, who has badgered the Fed all summer to cut not merely in its traditional quarter-point moves but to lower the fed funds rate quickly and aggressively. In the post-meeting statement, the committee again characterized economic activity as having “moderated” but added language saying that “job gains have slowed” and noted that inflation “has moved up and remains somewhat elevated.” Lower job growth and higher inflation are in conflict with the Fed’s twin goals of stable prices and full employment.  “Uncertainty about the economic outlook remains elevated” the Fed statement said. “The Committee is attentive to the risks to both sides of its dual mandate and judges that downside risks to employment have risen.” Markets showed mixed reaction to the developments, with the Dow Jones Industrial Average up more than 300 points but the S&P 500 and Nasdaq Composite posting losses. Treasury yields were modestly lower. At his post-meeting news conference, Fed Chair Jerome Powell echoed the concerns about the labor market. “The marked slowing in both the supply of and demand for workers is unusual in this less dynamic…
Share
BitcoinEthereumNews2025/09/18 02:44