The Bunni protocol, specialized in liquidity management, has temporarily paused the contracts.The Bunni protocol, specialized in liquidity management, has temporarily paused the contracts.

Bunni DEX under attack: approximately $2.4 million in stablecoins stolen on Ethereum, contracts paused

5 min read
bunni dex hack

A new attack has hit the LP funds on Ethereum: the Bunni protocol, specialized in liquidity management, has temporarily paused the contracts after an anomalous withdrawal estimated between approximately 2.3 and 2.4 million dollars – as reported by The Block and in line with the risks analyzed in the OpenZeppelin Security Report. Initial analyses indicate that the exploit may have exploited a vulnerability in the liquidity distribution function, improperly altering the LP shares.

According to the data collected by our on-chain analysis team, updated as of September 2, 2025, the suspicious transactions show repeated patterns and fractional transfers to multiple addresses, consistent with an attack aimed at exploiting rebalancing. Our cross-checks on public explorers indicate calibrated withdrawals in USDC and USDT for approximately 1.33 million dollars and 1.04 million dollars respectively. Industry analysts note that vulnerabilities related to rebalancing logic and oracles are a recurring cause in recent DeFi incidents.

In brief: what we know so far about the Bunni DEX hack

  • Who: Bunni, liquidity management protocol on Ethereum.
  • What: Draining of funds from smart contracts and operational suspension as a preventive security measure.
  • Dove: Ethereum network, with on-chain traceable movements.
  • When: Event detected in the days leading up to September 2, 2025; investigations are still ongoing.
  • How: Through the manipulation of liquidity rebalancing mechanisms, which led to miscalculations in the LP shares.

Timeline of Events

Essential Sequence

  • Detection of unusual movements in pools with stablecoin, particularly USDC and USDT.
  • Official communication from the team, confirmation of the incident, and suspension of contracts to contain the damage.
  • Preliminary on-chain analysis: estimated losses between approximately 2.3 and 2.4 million dollars, with repeated withdrawals and modulated amounts.
  • Initiation of technical checks on the liquidity distribution function and the rebalancing mechanism.

On-chain Details

  • Affected assets: stablecoin USDC (approximately 1.33 million dollars) and USDT (approximately 1.04 million dollars), which together converge on the estimate of total losses.
  • Pattern: a series of targeted trades with calibrated amounts to force an unfavorable rebalancing for LPs.
  • Addresses and hashes: examined by various blockchain analysis companies, although direct references to explorers have not yet been publicly released.

Various media, including The Block and BitcoinEthereumNews, have reported these elements, highlighting repeated patterns of suspicious transfers in the hours leading up to the suspension of the contracts.

Mechanics of Vulnerability

How Liquidity Distribution Works

Bunni employs a liquidity distribution function that allows capital to be allocated in specific price ranges, optimizing LP returns through transaction-induced rebalancing. The goal is to limit fund inertia; however, this approach can open new attack surfaces if the rebalancing logic is not sufficiently robust. 

Where the System Got Stuck

  • Manipulation of the curve through targeted and repeated trading operations.
  • Calculations of LP positions that, following rebalancing, resulted in incorrect shares.
  • Gradual draining of funds, orchestrated to evade the activation of automatic defensive triggers.

In essence, a non-resilient rebalancing logic allowed attackers to extract value from the LPs without immediately triggering alert mechanisms. An interesting aspect is the modularity of the amounts, indicative of a fine-tuned strategy.

Impact and Numbers

  • Estimated loss: approximately 2.3–2.4 million dollars.
  • Tokens involved: USDC and USDT.
  • Operational status: the contracts have been paused and the smart functions are currently suspended.
  • Critical point: the counting of LP shares and the management of liquidity during rebalancing processes.

Official Reactions and Context

The Bunni team has announced the suspension of contracts as an immediate security measure, clarifying that a post-incident analysis is underway to identify and correct the vulnerability. At the moment, no direct quotes or official statements with verifiable timestamps have been provided; investigations are ongoing and the priority remains securing the contracts and the remaining liquidity. 

Mitigation Measures

  • Ongoing audits on rebalancing functions and LP accounting mechanisms, including tests in adversarial scenarios.
  • Limitation of transaction size that can trigger sensitive rebalancing.
  • Implementation of circuit breaker and real-time monitoring of slippage and abnormal variations in LP quotes.
  • Use of timelock for critical changes and adoption of multisig operations for admin functions.
  • Creation of emergency funds or insurance coverage to mitigate impacts on users.

These countermeasures are essential in DeFi risk management.

Operational Guide for Liquidity Protocols

  • Execution of stress tests and simulations of economic attacks before official releases.
  • Implementation of rate limiting on functions that affect the distribution curve.
  • Active monitoring of alarm metrics such as slippage, changes in LP shares, and unexpected flows to wallets.
  • Periodic update of incident response procedures and drills to validate their effectiveness.
  • Use of reliable oracles and introduction of mathematical guardrails to prevent errors in calculations.

Next Steps for Users and Developers

  • Users: Monitor official protocol updates and check on-chain logs for any changes in the affected pools.
  • Developers: Complete the technical post-mortem, release temporary patches, and plan an independent audit focused on the liquidity management function and LP calculations.

What to Monitor

  • Tx hash and addresses confirmed on explorer like Etherscan or Blockscout for complete traceability.
  • Updates on the release of patches and the expected timeline for the reactivation of contracts.
  • Forensic reports from blockchain analysis companies and public audit results.
  • Any bounty programs or agreements for the return of misappropriated funds.

Conclusions

The attack on Bunni shows how innovations in liquidity distribution can introduce new attack surfaces when the rebalancing mechanism is not robust enough. 

The combination of curve manipulation and errors in LP calculations made it possible to drain approximately 2.3–2.4 million dollars in stablecoins. 

It must be said that the priority now is to complete a transparent post-incident analysis, correct the liquidity management logic, and introduce more rigorous defensive controls.

Numbers and addresses (summary)

  • Estimated amount: approximately 2.3–2.4 million dollars.
  • Token: USDC (approximately 1.33M) and USDT (approximately 1.04M).
  • Status: contracts on hold, investigations ongoing.
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Taiko and Chainlink to Unleash Reliable Onchain Data for DeFi Ecosystem

Taiko and Chainlink to Unleash Reliable Onchain Data for DeFi Ecosystem

Taiko and Chainlink Data Streams to deliver secure, high-speed onchain data by empowering next-generation DeFi protocols and institutional-grade adoption.
Share
Blockchainreporter2025/09/18 06:10
Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Share
BitcoinEthereumNews2025/09/18 00:41
One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02