Crypto2Community
HomeCrypto NewsReviewsGuidesGamblingTradingPress Release

Crypto 2 Community

  • About Us
  • Editorial Policy
  • Why Trust Us
  • Contact Us
  • Privacy Policy
  • Submit a Press Release

Cryptocurrency

  • Best Cryptos to Buy Now
  • Best Crypto Exchanges
  • How To Buy Cryptocurrency
  • Best Crypto Wallets
  • Best Altcoins to Buy

Gambling

  • Best Bitcoin Casinos
  • Best Ethereum Casinos
  • Best Crypto Live Casinos
  • Best Crypto Faucet Casinos
  • Provably Fair Bitcoin Casinos

Best Platforms

  • eToro Review
  • BC.Game Review
  • Jackbit Review
  • Metaspins Review
  • CryptoLeo Review

© 2026 Crypto2Community.com

CAUTION: The content presented on this platform is not intended as financial guidance, and we lack the authorization to offer investment advice. Any material found on this website should not be construed as an endorsement or recommendation of any specific trading strategy or investment decision. The information provided herein is of a general nature, and therefore it is essential to evaluate it in the context of your objectives, financial circumstances, and requirements.

Investment activities involve speculation and entail inherent risks to your capital. This website is not intended for utilization in jurisdictions where the described trading or investment activities are prohibited, and it should only be accessed by individuals who are legally permitted to do so. Depending on your country or state of residence, your investment may not be eligible for investor protection, hence it is advisable to conduct thorough research independently or seek appropriate guidance. While this website is accessible to you free of charge, please note that we may receive commissions from the companies featured on this site.

Disclosure: 18+ Rules regarding online gambling vary from country to country, please ensure you are following them and gamble responsibly. The content on this website is provided for entertainment purposes only. We may utilise affiliate links within our content, and receive commission.

Home/Crypto News
Crypto News

Bunni DEX Drained in $2.3M Smart Contract Exploit

Raymond Munene
Written byRaymond Munene
Crypto Writer
Fact checked byJoshua Downes
UpdatedSeptember 2, 2025
Our disclosure policy →
!

Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

ShareTweetShareLinkedIn
Bunni DEX Drained in $2.3M Smart Contract Exploit

Highlights:

  • Bunni lost $2.3 million in a smart contract exploit attack.
  • The vulnerability came from its Liquidity Distribution Function.
  • The exploiter moved funds to Aave, converting to stablecoins and ETH.

Bunni, a decentralized exchange built on Ethereum and Uniswap V4, lost $2.3 million when a security breach let hackers take advantage of a flaw in its liquidity mechanism. The attack happened early on Tuesday, and Certik’s on-chain analysts immediately identified it.

Advertisement

Banner

The attacker siphoned stablecoins, mostly USDC and USDT, from Bunni’s protocol. These assets were then sent through other decentralized finance (DeFi) platforms and finally deposited into Aave, a well-known lending platform that runs on Ethereum. According to the blockchain data, the wallet of the exploiter held $1.33 million of USDC and $1.04 million of USDT after the exploit.

#CertiKInsight 🚨

We have identified a $2.3M exploit on the @bunni_xyz BunniHub contract.https://t.co/lZB0vzSMQx

The exploiter has exfiltrated funds to 0xe04efd87f410e260cf940a3bcb8bc61f33464f2b.

Stay Vigilant!

— CertiK Alert (@CertiKAlert) September 2, 2025

Liquidity Distribution Function Caused the Smart Contract Exploit

At the center of the attack was a weakness in Bunni’s Liquidity Distribution Function (LDF). Bunni’s LDF is different from Uniswap’s default method because it tries to increase returns by moving liquidity around between different price ranges. This method was innovative, but it had a big flaw. 

Security researchers exposed the attacker’s approach to exploiting this function, which involved trades of very specific sizes. These trades messed up the LDF’s rebalancing logic, which made a mistake when calculating the value of liquidity provider (LP) shares. This allowed the attacker to receive more tokens than they should have been able to.

Victor Tran, the co-founder of KyberNetwork, said that the attacker “figured out they could manipulate the LDF by making trades of very specific sizes.” By doing these exact transactions over and over again, the exploiter was able to slowly take money without setting off any automated alarms. Furthermore, this smart contract exploit revealed a precision bug that could have arisen from a recent update to Bunni’s codebase. Despite the exploit, Bunnie had been audited previously.

1. Bunni is a liquidity hook that runs on top of UniswapV4. Instead of using UniswapV4’s normal system, Bunni has its own liquidity curve called LDF (Liquidity Distribution Function).

2. After each trade, Bunni checks if its LDF curve has changed since the last trade. If it has,… https://t.co/uCSWXyuAt2

— Victor Tran (@vutran54) September 2, 2025

Funds Routed Through Aave Following Exploit

After successfully extracting funds from Bunni, the attacker transferred them via several DeFi protocols. Eventually, the stolen assets landed in Aave, which deposited them into lending pools, making tracing and recovery more difficult. Analysts were able to confirm that the attacker’s final wallet held large balances in Aave USDC and USDT assets. Shortly after the exploit was discovered, at 3:04 a.m., Bunni’s team posted a statement on X confirming the breach.

The post reads:

“The Bunni app has been compromised with a security exploit. For the safety of users, we have paused all smart contract functions on all networks.”

Bunni engages with Euler Finance to handle some of its liquidity. However, Euler Labs CEO Michael Bentley explained that their protocol was not impacted by the exploit. He reassured users that none of the Euler systems were compromised during the incident.

The timing of the attack was notable. Bunni had just surpassed $60 million in total value locked and more than $1 billion in trading volume in August. Immediately following the attack, BUNNI prices dropped more than 35% within an hour. Further research into the full extent of the exploit is still underway. This incident happened in the midst of a general increase in crypto-related hacks. Over $163 million was lost in 16 crypto-related incidents during the month of August alone. This was a 15% increase from the previous month.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

Tags

Bunni DEXcrypto hackSECURITY BREACH
Raymond Munene
Crypto2CommunityContributor
Author

Raymond Munene

Raymond Munene is a crypto content writer who contributes to Crypto2Community. With over three years of experience, he is interested in Bitcoin, Blockchain, and Technical Analysis. Focusing on daily market analysis, his research helps traders and investors alike. His particular interest in cryptocurrency and blockchain aids his audience.

View full profile →
i
How we work

About Crypto2Community's Editorial Process

Crypto2Community's editorial policy is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict editorial policy and sourcing standards, and each page undergoes diligent review by our team of top crypto industry experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

More by this author

  • MiCA Deadline Could Push Thousands of European Crypto Firms Out of the Market
  • Michael Saylor’s Strategy Sets $2B Buyback Plan and Lifts STRC Dividend
  • Bank of Thailand Moves Ahead with Baht-Backed Stablecoin Plan
Continue reading

Related Articles

MiCA Deadline Could Push Thousands of European Crypto Firms Out of the MarketCrypto News
MiCA Deadline Could Push Thousands of European Crypto Firms Out of the Market
Crypto News3 hours ago
Chinedu Agbakwusi
By Chinedu Agbakwusi6/29/2026
Michael Saylor’s Strategy Sets $2B Buyback Plan and Lifts STRC DividendCrypto News
Michael Saylor’s Strategy Sets $2B Buyback Plan and Lifts STRC Dividend
Crypto News3 hours ago
Raymond Munene
By Raymond Munene6/29/2026
Bank of Thailand Moves Ahead with Baht-Backed Stablecoin PlanCrypto News
Bank of Thailand Moves Ahead with Baht-Backed Stablecoin Plan
Crypto News8 hours ago
Syed Ali Haider
By Syed Ali Haider6/29/2026

Advertisement

Banner

Advertisement

Banner

🔥Latest offers

Play Now

9.85 Stars

🔥 Get up to 60% with all rewards

Play Now →

Claim Bonus

9.65 Stars

💸 300% deposit bonus up to 20,000 USD

Claim Bonus →

Visit eToro

9.95 Stars

Best Crypto Exchange 2025

Visit eToro →

Virtual currencies are highly volatile. Your capital is at risk.

Visit KuCoin

9.55 Stars

Trading features & low fees

Visit KuCoin →

Popular Topics

  • Sei Price Prediction 2025, 2030, 2040
  • Uniswap Price Prediction 2025, 2030, 2040
  • Near Protocol Price Prediction 2025, 2030, 2040
  • Loopring Price Prediction 2025, 2030, 2040
  • Chainlink Price Prediction 2025, 2030, 2040

Trending News

  • MiCA Deadline Could Push Thousands of European Crypto Firms Out of the Market
  • Michael Saylor’s Strategy Sets $2B Buyback Plan and Lifts STRC Dividend
  • Bank of Thailand Moves Ahead with Baht-Backed Stablecoin Plan
  • David Schwartz Proposes XRP Ledger Plan to Stop Front-Running Attacks
  • Crypto Weekly Market Wrap June 29 – Regulatory Shifts, ETF Outflows, Exploits, and Treasury Moves
  • Vitalik Buterin Says Obfuscation Could Unlock Stronger Privacy for Blockchains
  • Best Cryptocurrencies to Invest in Today, June 29 – Solana, Tron, Chainlink
  • BIS Warns Stablecoins May Add New Risks to Global Financial Stability
  • USDT Premium in India Jumps Above 8.5% as ED Crackdown Tightens Stablecoin Supply
  • Best Live Sports Betting in 2026 – Top In-Play Betting Sites USA
  • Best US Live Roulette Casinos In 2026 – Play Roulette Online Today!
  • Best Offshore Sportsbooks – 2026’s Top Overseas Betting Sites For USA
  • Best Online Roulette Apps of 2026: Mobile Real Money Roulette Sites
  • Best Live Baccarat US Casinos For 2026 – Play For Real Money
  • Best Online Casino Games for Real Money in 2026
  • Best Online Casinos on Reddit – Compare the Top Reddit Online Casinos
  • Instant Withdrawal Casinos in 2026 – Top Gambling Sites with Fast Payouts
  • Taiko Outlines Staged Recovery Plan After $1.7M Bridge Exploit
  • Brian Armstrong Responds After Zcash Founder Criticizes Coinbase Betting Prompts
  • Grayscale Says Strategy May Need $3 Billion Bitcoin Sale to Restore Confidence