• Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

06/09/2025 - Updated On 07/07/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
SEC delays decision on 21Shares SUI ETF until December

SEC pushes 21Shares SUI ETF decision back to December

09/06/2025
Sora ventures Bitcoin treasury targets $1B in Asia

Sora Ventures sets $1B target for Asia Bitcoin treasury push

09/06/2025
Kazakhstan adopts USD-pegged stablecoin for regulatory fees

Kazakhstan rolls out USD-pegged stablecoin for regulatory fee payments

09/06/2025
  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

06/09/2025 - Updated On 07/07/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
SEC delays decision on 21Shares SUI ETF until December

SEC pushes 21Shares SUI ETF decision back to December

09/06/2025
Sora ventures Bitcoin treasury targets $1B in Asia

Sora Ventures sets $1B target for Asia Bitcoin treasury push

09/06/2025
Kazakhstan adopts USD-pegged stablecoin for regulatory fees

Kazakhstan rolls out USD-pegged stablecoin for regulatory fee payments

09/06/2025
Saturday, September 6, 2025
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Contact
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

Bunni hit by $8.4M flash-loan exploit in latest DeFi breach

Developers blame a rounding bug as the Bunni flash-loan exploit exposes critical vulnerabilities in automated market makers.

by Moses Edozie
7 hours ago
in Crypto News
Reading Time: 3 mins read
0
Bunni flash-loan exploit drains $8.4M from DeFi protocol

Bunni flash-loan exploit drains $8.4M from DeFi protocol

Share on FacebookShare on Twitter

Decentralized finance protocol Bunni has confirmed it lost $8.4 million on September 2 in what is now being described as the Bunni flash-loan exploit. The attacker executed a complex strategy that targeted liquidity pools on Ethereum and Unichain, manipulating prices and exploiting a flaw in the protocol’s smart contract logic.

The exploit began when the attacker borrowed 3 million USDT through a flash loan, using it to distort the USDC/USDT pool’s spot price. With the pool’s balance pushed to extreme levels, they initiated 44 micro-withdrawals that exposed a rounding error in Bunni’s code. This sequence drained liquidity by more than 80%, leaving the pools vulnerable to further manipulation.

Blockchain security firm Cyfrin later confirmed that the bug stemmed from how the protocol rounded balances during withdrawals. While designed as a conservative safeguard, the rounding mechanism created conditions that could be repeatedly exploited.

“This was a textbook case of how small coding oversights in DeFi can escalate into multimillion-dollar losses when paired with flash-loan strategies,” — Cyfrin analyst, in a report following the Bunni flash-loan exploit.

The scale of losses and ongoing investigation

The Bunni flash-loan exploit ultimately netted the attacker around 1.33 million USDC and 1 million USDT, with stolen assets now spread across two wallets. Investigators tracked the funds but reached a dead end after discovering that the wallets were initially funded through Tornado Cash, a sanctioned privacy tool.

Bunni’s largest pool, the Unichain USDC/USD₮0 pair, escaped the attack. Analysts suggest the only reason it remained safe was the absence of sufficient flash-loan liquidity to mount a comparable assault. Exploiting that pool would have required $17 million in borrowed assets, but only $11 million was accessible at the time.

In response, Bunni has contacted the attacker directly on-chain, offering a 10% bounty if the funds are returned. Centralized exchanges have also been alerted in case the exploiter attempts to convert the stolen tokens.

“While we are engaging law enforcement and security partners, our first step is to negotiate recovery directly,” — Bunni development team, in its official statement on the Bunni flash-loan exploit.

Source: Bunni_xyz

Protocol response and code changes

Operations on Bunni were paused immediately after the breach, with deposits and swaps frozen as a precaution. Withdrawals were later reopened to allow liquidity providers to reclaim their remaining assets. Developers announced that the immediate fix involved altering the rounding direction in the affected function, neutralizing the exploit vector.

However, the team acknowledged that more extensive testing and upgrades will be needed before the platform fully resumes. The exploit highlighted how new DeFi designs, such as Bunni’s Liquidity Density Functions (LDFs), require heightened scrutiny before being deployed at scale.

“We spent years building Bunni because we believe it represents the future of automated market makers,” — Bunni team statement. “This setback is painful, but it strengthens our resolve to improve security, testing, and resilience.”

At its peak, Bunni held over $80 million in total value locked (TVL). Following the Bunni flash-loan exploit, that figure has dropped to just above $50 million.

A wider trend of crypto security breaches

The Bunni flash-loan exploit is the latest in a series of high-profile incidents undermining confidence in decentralized finance. According to blockchain security firm PeckShield, more than $163 million was stolen across 16 major attacks in August alone, making it the third-worst month for crypto security in 2025.

Recent incidents include a $13.5 million phishing scam targeting a Venus Protocol user, a $91 million social engineering theft involving 783 BTC, and a $54 million hot wallet breach at Turkish exchange BtcTurk.

Security experts warn that both technical flaws, like those behind the Bunni flash-loan exploit, and human-driven schemes such as phishing will continue to challenge the sector. With DeFi protocols growing in complexity, the pressure is mounting on developers to adopt rigorous security audits and on regulators to consider oversight mechanisms.

“The lesson from the Bunni flash-loan exploit and others is clear: innovation must be matched with robust safeguards, or the risks will overshadow the potential,” — PeckShield spokesperson, in a statement on industry-wide vulnerabilities.

Tags: BunniDeFi flash loan hacksEthereum liquidity exploitFlash-Loan ExploithackUnichain crypto attack
Share197Tweet123
Moses Edozie

Moses Edozie

Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.

  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

06/09/2025 - Updated On 07/07/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
SEC delays decision on 21Shares SUI ETF until December

SEC pushes 21Shares SUI ETF decision back to December

09/06/2025
Sora ventures Bitcoin treasury targets $1B in Asia

Sora Ventures sets $1B target for Asia Bitcoin treasury push

09/06/2025
Kazakhstan adopts USD-pegged stablecoin for regulatory fees

Kazakhstan rolls out USD-pegged stablecoin for regulatory fee payments

09/06/2025
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Contact

Copyright © 2025 - The Bit Gazette.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?