Cryptopolitan
2025-09-02 08:12:47

BunniXYZ Ethereum exchange suffers $2.3M breach

The BunniXYZ Ethereum exchange saw a series of unauthorized outflows. On-chain investigators identified the event as a hack, with losses of around $2.3M. BunniXYZ, an Ethereum decentralized exchange, has been exploited through one of its smart contracts. The hacker moved mostly stablecoins, for a total loss of $2.3M. #CertiKInsight 🚨 We have identified a $2.3M exploit on the @bunni_xyz BunniHub contract. https://t.co/lZB0vzSMQx The exploiter has exfiltrated funds to 0xe04efd87f410e260cf940a3bcb8bc61f33464f2b. Stay Vigilant! — CertiK Alert (@CertiKAlert) September 2, 2025 Based on the transaction history , the hacker attacked USDT and USDC vaults, then moved the tokens through the Ethereum ecosystem, ending up with a mix of ETH and stablecoins. Within the first minutes, the BunniXYZ project recognized the attack against its app, closing all smart contracts. Soon after the hack, the exploiter continued to swap funds into ETH through other DeFi protocols. In the hour after the attack, the hacker did not yet move or mix the funds, except for the initial movements through DeFi protocols. The attack against BunniXYZ is part of the latest series of relatively minor hacks, stealing less than $10M. Even the relatively small attacks often cost the reputation of protocols and destroy new DeFi hubs. One of the most recent smart contract exploits was against BetterBank, as Cryptopolitan reported . Such attacks raise suspicions of insider jobs, or malicious code injected into Web3 by DPRK hackers. BunniXYZ attacked at the peak BunniXYZ is a DEX using both Ethereum and Unichain. The new market also uses the Uniswap V4 technology to create special vaults and markets with more complex trading rules. As with other markets, BunniXYZ was attacked soon after reaching a local peak of value locked. At the end of August, the exchange carried up to $60M in its vaults. The market was still relatively small, after launching in February and finding its place among new DeFi protocols. August was also one of the most successful months for the DEX, with over $1B in volumes. The exchange was specifically building liquidity for rehypothecation , while avoiding liquidations during market downturns. The DEX liquidity was also linked to Euler Protocol for passive income. BunniXYZ rode on the expanded volumes of Uniswap V4, as the protocol drew in over $393M to its vaults on Ethereum and $298M on Unichain. Hacker exploited BunniXYZ liquidity calculation Post-hack analysis showed BunniXYZ was vulnerable due to its specific liquidity recalculation contract. The DEX is a liquidity hook, using the Uniswap V4 technology. However, instead of using Uniswap’s liquidity calculation, BunniXYZ recalculates the Liquidity Distribution Function. The exploiter discovered the Liquidity Distribution Function could break from trades of specific sizes. This meant the smart contract would pay out more tokens from the liquidity pool than owned in reality, ending up draining the exchange. The attacker had to repeat multiple transactions to finally accrue $2.3M, then swap them out for ETH. He then ended up depositing the ETH into Aave, holding $1.33M in AethUSDC and $1M in AethUSDT based on the wallet’s final balance. BunniXYZ has undergone previous audits, but the LDF bug may have arrived with a later version of the exchange. The most probable cause is a precision bug, which required the hacker to perform multiple transactions to accrue a bigger balance based on the flawed recalculation. Want your project in front of crypto’s top minds? Feature it in our next industry report, where data meets impact.

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.