The post Ethereum exchange BunniXYZ drained for $2.3M in smart contract exploit appeared on BitcoinEthereumNews.com. The BunniXYZ Ethereum exchange saw a series of unauthorized outflows. On-chain investigators identified the event as a hack, with losses of around $2.3M.  BunniXYZ, an Ethereum decentralized exchange, has been exploited through one of its smart contracts. The hacker moved mostly stablecoins, for a total loss of $2.3M.  #CertiKInsight 🚨 We have identified a $2.3M exploit on the @bunni_xyz BunniHub contract.https://t.co/lZB0vzSMQx The exploiter has exfiltrated funds to 0xe04efd87f410e260cf940a3bcb8bc61f33464f2b. Stay Vigilant! — CertiK Alert (@CertiKAlert) September 2, 2025 Based on the transaction history, the hacker attacked USDT and USDC vaults, then moved the tokens through the Ethereum ecosystem, ending up with a mix of ETH and stablecoins. Within the first minutes, the BunniXYZ project recognized the attack against its app, closing all smart contracts.  Soon after the hack, the exploiter continued to swap funds into ETH through other DeFi protocols.  In the hour after the attack, the hacker did not yet move or mix the funds, except for the initial movements through DeFi protocols. The attack against BunniXYZ is part of the latest series of relatively minor hacks, stealing less than $10M.  Even the relatively small attacks often cost the reputation of protocols and destroy new DeFi hubs. One of the most recent smart contract exploits was against BetterBank, as Cryptopolitan reported. Such attacks raise suspicions of insider jobs, or malicious code injected into Web3 by DPRK hackers.  BunniXYZ attacked at the peak BunniXYZ is a DEX using both Ethereum and Unichain. The new market also uses the Uniswap V4 technology to create special vaults and markets with more complex trading rules.  As with other markets, BunniXYZ was attacked soon after reaching a local peak of value locked. At the end of August, the exchange carried up to $60M in its vaults. The market was still relatively small, after launching in… The post Ethereum exchange BunniXYZ drained for $2.3M in smart contract exploit appeared on BitcoinEthereumNews.com. The BunniXYZ Ethereum exchange saw a series of unauthorized outflows. On-chain investigators identified the event as a hack, with losses of around $2.3M.  BunniXYZ, an Ethereum decentralized exchange, has been exploited through one of its smart contracts. The hacker moved mostly stablecoins, for a total loss of $2.3M.  #CertiKInsight 🚨 We have identified a $2.3M exploit on the @bunni_xyz BunniHub contract.https://t.co/lZB0vzSMQx The exploiter has exfiltrated funds to 0xe04efd87f410e260cf940a3bcb8bc61f33464f2b. Stay Vigilant! — CertiK Alert (@CertiKAlert) September 2, 2025 Based on the transaction history, the hacker attacked USDT and USDC vaults, then moved the tokens through the Ethereum ecosystem, ending up with a mix of ETH and stablecoins. Within the first minutes, the BunniXYZ project recognized the attack against its app, closing all smart contracts.  Soon after the hack, the exploiter continued to swap funds into ETH through other DeFi protocols.  In the hour after the attack, the hacker did not yet move or mix the funds, except for the initial movements through DeFi protocols. The attack against BunniXYZ is part of the latest series of relatively minor hacks, stealing less than $10M.  Even the relatively small attacks often cost the reputation of protocols and destroy new DeFi hubs. One of the most recent smart contract exploits was against BetterBank, as Cryptopolitan reported. Such attacks raise suspicions of insider jobs, or malicious code injected into Web3 by DPRK hackers.  BunniXYZ attacked at the peak BunniXYZ is a DEX using both Ethereum and Unichain. The new market also uses the Uniswap V4 technology to create special vaults and markets with more complex trading rules.  As with other markets, BunniXYZ was attacked soon after reaching a local peak of value locked. At the end of August, the exchange carried up to $60M in its vaults. The market was still relatively small, after launching in…

Ethereum exchange BunniXYZ drained for $2.3M in smart contract exploit

For feedback or concerns regarding this content, please contact us at [email protected]

The BunniXYZ Ethereum exchange saw a series of unauthorized outflows. On-chain investigators identified the event as a hack, with losses of around $2.3M. 

BunniXYZ, an Ethereum decentralized exchange, has been exploited through one of its smart contracts. The hacker moved mostly stablecoins, for a total loss of $2.3M. 

Based on the transaction history, the hacker attacked USDT and USDC vaults, then moved the tokens through the Ethereum ecosystem, ending up with a mix of ETH and stablecoins. Within the first minutes, the BunniXYZ project recognized the attack against its app, closing all smart contracts. 

Soon after the hack, the exploiter continued to swap funds into ETH through other DeFi protocols. 

In the hour after the attack, the hacker did not yet move or mix the funds, except for the initial movements through DeFi protocols. The attack against BunniXYZ is part of the latest series of relatively minor hacks, stealing less than $10M. 

Even the relatively small attacks often cost the reputation of protocols and destroy new DeFi hubs. One of the most recent smart contract exploits was against BetterBank, as Cryptopolitan reported. Such attacks raise suspicions of insider jobs, or malicious code injected into Web3 by DPRK hackers. 

BunniXYZ attacked at the peak

BunniXYZ is a DEX using both Ethereum and Unichain. The new market also uses the Uniswap V4 technology to create special vaults and markets with more complex trading rules. 

As with other markets, BunniXYZ was attacked soon after reaching a local peak of value locked. At the end of August, the exchange carried up to $60M in its vaults. The market was still relatively small, after launching in February and finding its place among new DeFi protocols. 

August was also one of the most successful months for the DEX, with over $1B in volumes. The exchange was specifically building liquidity for rehypothecation, while avoiding liquidations during market downturns. The DEX liquidity was also linked to Euler Protocol for passive income.

BunniXYZ rode on the expanded volumes of Uniswap V4, as the protocol drew in over $393M to its vaults on Ethereum and $298M on Unichain.

Hacker exploited BunniXYZ liquidity calculation

Post-hack analysis showed BunniXYZ was vulnerable due to its specific liquidity recalculation contract. The DEX is a liquidity hook, using the Uniswap V4 technology. However, instead of using Uniswap’s liquidity calculation, BunniXYZ recalculates the Liquidity Distribution Function. 

The exploiter discovered the Liquidity Distribution Function could break from trades of specific sizes. This meant the smart contract would pay out more tokens from the liquidity pool than owned in reality, ending up draining the exchange. The attacker had to repeat multiple transactions to finally accrue $2.3M, then swap them out for ETH. He then ended up depositing the ETH into Aave, holding $1.33M in AethUSDC and $1M in AethUSDT based on the wallet’s final balance. 

BunniXYZ has undergone previous audits, but the LDF bug may have arrived with a later version of the exchange. The most probable cause is a precision bug, which required the hacker to perform multiple transactions to accrue a bigger balance based on the flawed recalculation.

If you’re reading this, you’re already ahead. Stay there with our newsletter.

Source: https://www.cryptopolitan.com/ethereum-exchange-bunnixyz-drained-2-3m/

Market Opportunity
Threshold Logo
Threshold Price(T)
$0.006733
$0.006733$0.006733
-2.56%
USD
Threshold (T) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

$683M to Nscale for 60,000 GPUs by 2026

$683M to Nscale for 60,000 GPUs by 2026

The post $683M to Nscale for 60,000 GPUs by 2026 appeared on BitcoinEthereumNews.com. Nvidia will invest $683 million in Nscale, the spin-off of Arkon Energy spun off in May 2024 to offer AI cloud services in Europe, with the goal of bringing up to 60,000 GPUs to the United Kingdom. The capital injection, in line with the push towards advanced AI infrastructure, is part of a joint effort to strengthen strategic computing capabilities in the region; the rollout is planned in stages between 2025 and 2026. The operation also coincides with the UK government’s plan to accelerate AI adoption and security, outlined by the government on January 13, 2025. According to data collected by industry analysts, updated as of September 17, 2025, projects that convert mining sites into AI nodes can reduce the time-to-market compared to new facilities by about 30–50%. Our field market analyses indicate typical improvements in PUE in the range of 10–20% after energy optimization interventions and the introduction of liquid cooling. Operators we have monitored also report that long-term energy contracts and proximity to major interconnection nodes are determining factors for the economic sustainability of the clusters. The Agreement in Brief: Figures, Goals, Timeline Investment: $683 million allocated to Nscale. Target capacity: up to 60,000 GPUs deployed in data centers in the United Kingdom. Timeline: phased rollout activity scheduled between 2025 and 2026. Origin Nscale: spin-off from Arkon Energy, created in May 2024 to enter the European market for AI cloud services. From miner to cloud AI: the Nscale spinoff Nscale is born from the conversion of mining assets into nodes for AI workloads, transforming facilities designed for energy-intensive and single-use operations into platforms with high computational value and greater flexibility. The strategy — based on the reuse of existing sites and network connections — allows for reduced startup times and capex, a significant advantage when targeting clusters dedicated…
Share
BitcoinEthereumNews2025/09/18 19:22
WTI nears multi-month high as Hormuz closure fuels supply concerns

WTI nears multi-month high as Hormuz closure fuels supply concerns

The post WTI nears multi-month high as Hormuz closure fuels supply concerns appeared on BitcoinEthereumNews.com. West Texas Intermediate (WTI) US Crude Oil prices
Share
BitcoinEthereumNews2026/03/03 09:57
Vitalik Buterin Reveals Ethereum’s Long-Term Focus on Quantum Resistance

Vitalik Buterin Reveals Ethereum’s Long-Term Focus on Quantum Resistance

TLDR Ethereum focuses on quantum resistance to secure the blockchain’s future. Vitalik Buterin outlines Ethereum’s long-term development with security goals. Ethereum aims for improved transaction efficiency and layer-2 scalability. Ethereum maintains a strong market position with price stability above $4,000. Vitalik Buterin, the co-founder of Ethereum, has shared insights into the blockchain’s long-term development. During [...] The post Vitalik Buterin Reveals Ethereum’s Long-Term Focus on Quantum Resistance appeared first on CoinCentral.
Share
Coincentral2025/09/18 00:31