Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Decentralized Exchange BunniXYZ Loses $8.4M in Liquidity Exploit

Decentralized Exchange BunniXYZ Loses $8.4M in Liquidity Exploit

CryptoNewsNetCryptoNewsNet2025/09/02 12:20
By:decrypt.co

Decentralized exchange (DEX) BunniXYZ has reportedly lost $8.4 million to a liquidity-based security exploit.

According to on-chain security firm Hacken, $6 million of the DEX's funds was stolen via the Unichain blockchain and $2.4 million via Ethereum. All Unichain funds were then bridged to Ethereum using the Across Protocol.

Confirming the attack in a tweet, BunniXYZ said that it had paused all smart contract activity on its network and was “actively investigating” the circumstances of the attack. It added that it would provide updates soon.

🚨 The Bunni app has been affected by a security exploit. As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon. Thank you for your patience.

Founded in February 2025, BunniXYZ is based on automated market maker Uniswap v4, and primarily uses the Ethereum and Unichain blockchains. It currently has a cross-chain Total Value Locked (TVL) of just over $50 million according to DeFiLlama, though it exceeded $80 million at one point earlier this August.

Michael Bentley, co-founder of lending protocol Euler, advised users to remove their funds from Bunni in a tweet, adding that while the DEX rebalances funds in and out of Euler, the lending protocol is "not affected or at risk." Euler endured a major exploit of its own in 2023 that saw hackers steal nearly $200 million, the bulk of which was later recovered.

What happened?

According to on-chain analyst Victor Tran, co-founder of Kyber Network, hackers manipulated Bunni’s “liquidity curve,” also known as its LDF (Liquidity Density Function). This is the system that calculates how much extra liquidity exists within the exchange and rebalances its liquidity pool to keep the right ratio of tokens.

1. Bunni is a liquidity hook that runs on top of UniswapV4. Instead of using UniswapV4’s normal system, Bunni has its own liquidity curve called LDF (Liquidity Distribution Function).

2. After each trade, Bunni checks if its LDF curve has changed since the last trade. If it has,…

Tran said hackers manipulated this LDF “by making trades of very specific sizes.” This caused the rebalancing calculation to break, producing incorrect results for how much each liquidity pool share should own.

By repeating this process, hackers allegedly withdrew more tokens than they should have been able to from Bunni.

Bunni itself has not yet confirmed the mechanism behind the attack.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

OneFootball In-depth Analysis: Turning "Watching Football" into "Owning and Co-creating"

Football starts with the community, and OneFootball will ensure that early supporters are rewarded, rather than marginalized, in the process of co-building the club.

Chaincatcher2025/09/04 06:38
OneFootball In-depth Analysis: Turning "Watching Football" into "Owning and Co-creating"

XRP News Today: Ripple's RLUSD Targets Africa's Financial Gaps with $700M Stablecoin Push

- Ripple launches $700M RLUSD stablecoin in Africa via Trident Digital, aiming to enhance digital payments and financial inclusion through regulatory compliance and USD-backed liquidity. - Trident commits $500M to XRP treasury, aligning with Ripple’s ecosystem to strengthen DeFi integration and blockchain innovation via staking mechanisms in African markets. - RLUSD targets cross-border payment gaps with low-cost, real-time settlements, leveraging Ripple’s CBDC experience and global regulatory partnerships

ainvest2025/09/04 05:26
XRP News Today: Ripple's RLUSD Targets Africa's Financial Gaps with $700M Stablecoin Push

Bitcoin News Today: Regulators Power $4.2T US Crypto Surge as ETFs Ignite Mainstream Buy-In

- The US leads global crypto adoption with $4.2T in fiat-to-crypto onramps, four times higher than any other nation. - Bitcoin dominates inflows at $4.6T, while spot ETFs attracted $54.5B since 2024, driving institutional and retail participation. - APAC saw 69% annual on-chain growth led by India, while Eastern Europe tops per-capita adoption due to economic instability. - Divergent global regulations emerge, with the US GENIUS Act and EU MiCA reflecting contrasting approaches to crypto oversight.

ainvest2025/09/04 05:26
Bitcoin News Today: Regulators Power $4.2T US Crypto Surge as ETFs Ignite Mainstream Buy-In

XRP News Today: BlockDAG’s Hybrid Model Could Disrupt 2025’s Crypto Power Rankings

- BlockDAG's $389M presale and 3M users via X1 miner app highlight its rapid adoption in crypto. - Hybrid DAG-PoW model with EVM compatibility aims to solve scalability issues, attracting 300+ dApp developers. - $0.03 presale price targets $0.05 listing, competing with XRP and Cardano in 2025's institutional adoption race. - Physical miners (X10/X30/X100) and mobile mining blend retail/institutional participation, boosting network decentralization.

ainvest2025/09/04 05:26
XRP News Today: BlockDAG’s Hybrid Model Could Disrupt 2025’s Crypto Power Rankings