Crypto2Community
HomeCrypto NewsReviewsGuidesGamblingTradingPress Release

Crypto 2 Community

  • About Us
  • Editorial Policy
  • Why Trust Us
  • Contact Us
  • Privacy Policy
  • Submit a Press Release

Cryptocurrency

  • Best Cryptos to Buy Now
  • Best Crypto Exchanges
  • How To Buy Cryptocurrency
  • Best Crypto Wallets
  • Best Altcoins to Buy

Gambling

  • Best Bitcoin Casinos
  • Best Ethereum Casinos
  • Best Crypto Live Casinos
  • Best Crypto Faucet Casinos
  • Provably Fair Bitcoin Casinos

Best Platforms

  • eToro Review
  • BC.Game Review
  • Jackbit Review
  • Metaspins Review
  • CryptoLeo Review

© 2026 Crypto2Community.com

CAUTION: The content presented on this platform is not intended as financial guidance, and we lack the authorization to offer investment advice. Any material found on this website should not be construed as an endorsement or recommendation of any specific trading strategy or investment decision. The information provided herein is of a general nature, and therefore it is essential to evaluate it in the context of your objectives, financial circumstances, and requirements.

Investment activities involve speculation and entail inherent risks to your capital. This website is not intended for utilization in jurisdictions where the described trading or investment activities are prohibited, and it should only be accessed by individuals who are legally permitted to do so. Depending on your country or state of residence, your investment may not be eligible for investor protection, hence it is advisable to conduct thorough research independently or seek appropriate guidance. While this website is accessible to you free of charge, please note that we may receive commissions from the companies featured on this site.

Disclosure: 18+ Rules regarding online gambling vary from country to country, please ensure you are following them and gamble responsibly. The content on this website is provided for entertainment purposes only. We may utilise affiliate links within our content, and receive commission.

Home/Crypto News
Crypto News

Bunni Reveals Smart Contract Rounding Flaw Behind $8.4M Flash Loan Exploit

Author
Raymond Munene
Raymond Munene
Crypto Writer
Fact Checked by Joshua Downes
Last updated: September 5, 2025
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
TweetShareLinkedIn0
Bunni Reveals Smart Contract Rounding Flaw Behind $8.4M Flash Loan Exploit

Highlights:

  • Bunni cites a rounding flaw in withdrawals as the cause of the $8.4M flash loan exploit.
  • The attacker drained funds using 44 small withdrawals and price manipulation.
  • Bunni offers a 10% bounty to recover the remaining stolen assets.

Decentralized exchange Bunni has identified the root cause of the recent flash loan exploit that saw its protocol lose $8.4 million. In a detailed post-mortem published on September 4, the team found that they had a bug in the logic of withdrawals in their smart contract. This vulnerability enabled an attacker to manipulate liquidity in two pools, the weETH/ETH pair on Unichain and the USDC/USDT pair on Ethereum, with the help of a flash loan.

Advertisement

Banner

According to Bunni, the exploit worked because of a rounding error that incorrectly adjusted pool balances during withdrawals. Although the contract was intended to round values conservatively, the strategy broke down under repeated small transactions. This created an opportunity for an attacker to siphon off the majority of the pools’ liquidity using very little capital.

🚨 Exploit Update: The Bunni team has completed analysis of the recent exploit. The details are available in this post mortem blog post (link in comment).

Withdrawals have been unpaused, so LPs are now free to withdraw their assets. All other operations remain paused.

— Bunni (@bunni_xyz) September 4, 2025

Flash Loan Exploit Rooted in Withdrawal Rounding Bug

Bunni said the attacker started by flash-borrowing a total of 3 million USDT. This was then used to drive up the spot price of the pool by using a series of swaps. These swaps reduced the USDC balance to only 28 wei, essentially destabilizing the liquidity at the pool. Once the pool was revealed, the attacker made 44 small withdrawals, each one taking advantage of the flawed rounding logic.

The contract logic assumed that the rounding down of active balances would protect the pool. However, the attacker used this in multiple transactions. These micro-withdrawals, although still consistent with healthy system levels, gradually decreased the amount of actual liquidity in the pool. The attacker then completed the attack by making a large swap to move prices up and then a reverse trade at the manipulated rate.

Bunni verified that this series of transactions enabled the attacker to repay the original loan while pocketing around $1.33 million in USDC and $1 million in USDT. The stolen funds were then funneled through Tornado Cash, which made them harder to trace. Although Bunni was able to trace the assets to two wallets, no further progress has been made in identifying the attacker.

Following the post-mortem release, the Bunni token price has seen a surge of 25%, pushing its price to $0.005352. Despite this latest surge, the token is down by 40% and 55% on the weekly and monthly charts, respectively.

Source: CoinGecko

Bunni’s Response and Fixes Moving Forward

In response, the rounding bug in the withdrawal logic was patched by Bunni quickly. The patch modified the way idle and active balances are computed for withdrawals. Blockchain security firm Cyfrin tested the update on all affected networks and proved it to be effective. Withdrawals have since been reactivated, but swaps and deposits are still on hold, with further analysis being done.

In order to recover the stolen funds, Bunni approached the attacker with a white-hat bounty offer. Under the proposal, the attacker would keep 10% of the funds, which is approximately $840,000, if the other funds are returned. At the same time, Bunni has alerted centralized exchanges and law enforcement to keep a lookout for any transfers of the stolen assets.

Interestingly, Bunni pointed out that in the attack, its largest pool on Unichain was not attacked. However, this was not the case because of superior security. The team explained that Unichain’s flash loan providers did not have enough liquidity to fund an exploit of that magnitude, which ended up protecting the pool.

The vulnerability was identified as a line of code in the function called BunniHubLogic::withdraw(). The team admitted that its testing framework was unable to detect the problem during audits. As a result, Bunni now aims to further expand its fuzz and invariant testing suite to make protocols more resilient.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

Tags

Bunni DEXcrypto hackExploit
Raymond Munene
Author

Raymond Munene

Raymond Munene is a crypto content writer who contributes to Crypto2Community. With over three years of experience, he is interested in Bitcoin, Blockchain, and Technical Analysis. Focusing on daily market analysis, his research helps traders and investors alike. His particular interest in cryptocurrency and blockchain aids his audience.

View full profile ›

ℹ️About Crypto2Community's Editorial Process

Crypto2Community's editorial policy is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict editorial policy and sourcing standards, and each page undergoes diligent review by our team of top crypto industry experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

More by this author:

  • Franklin Templeton and Payward Partner to Expand Tokenized Assets for Institutions
  • Ethereum Foundation Unstakes $50M ETH From Lido After Months of Aggressive Staking
  • Bitcoin Price Analysis – BTC Stalls Ahead of Inflation Data as $89K Target Stays in Sight

Related Articles:

Franklin Templeton and Payward Partner to Expand Tokenized Assets for Institutions
Franklin Templeton and Payward Partner to Expand Tokenized Assets for Institutions
Crypto News9 hours ago
Syed Ali Haider
By Syed Ali Haider5/12/2026
Ethereum Foundation Unstakes $50M ETH From Lido After Months of Aggressive Staking
Ethereum Foundation Unstakes $50M ETH From Lido After Months of Aggressive Staking
Crypto News13 hours ago
Austin Mwendia
By Austin Mwendia5/12/2026
Bitcoin Price Analysis – BTC Stalls Ahead of Inflation Data as $89K Target Stays in Sight
Bitcoin Price Analysis – BTC Stalls Ahead of Inflation Data as $89K Target Stays in Sight
Crypto News13 hours ago
Syed Ali Haider
By Syed Ali Haider5/12/2026

Advertisement

Banner

Advertisement

Banner

🔥Latest offers

Play Now

9.85 Stars

🔥 Get up to 60% with all rewards

Claim Bonus

9.65 Stars

💸 300% deposit bonus up to 20,000 USD

Visit eToro

9.95 Stars

Best Crypto Exchange 2025

Virtual currencies are highly volatile. Your capital is at risk.

Visit KuCoin

9.55 Stars

Trading features & low fees

Popular Topics

  • Sei Price Prediction 2025, 2030, 2040
  • Uniswap Price Prediction 2025, 2030, 2040
  • Near Protocol Price Prediction 2025, 2030, 2040
  • Loopring Price Prediction 2025, 2030, 2040
  • Chainlink Price Prediction 2025, 2030, 2040

Trending News

  • Franklin Templeton and Payward Partner to Expand Tokenized Assets for Institutions
  • Ethereum Foundation Unstakes $50M ETH From Lido After Months of Aggressive Staking
  • Bitcoin Price Analysis – BTC Stalls Ahead of Inflation Data as $89K Target Stays in Sight
  • Three Tennessee Men Indicted in Alleged $6.5M Crypto Robbery Spree
  • Ethereum Price Prediction – Tight Supply Could Help ETH Recover to $3K
  • Bitcoin Still Falls Short As A Safe-Haven Asset, Says Ray Dalio
  • Best Altcoins to Watch Today, May 12 – Zcash, Toncoin, Cronos
  • TRX Gains 26% in 3 Months Despite Growing Market Concerns Over Tron and Justin Sun
  • Senate Releases 309-Page CLARITY Act Draft Ahead of May 14 Markup
  • BitMine’s Ethereum Holdings Reach 5.21 Million ETH as Total Assets Hit $13.4 Billion
  • Crypto.com Wins UAE License to Process Dubai Government Crypto Payments
  • SUI Price Forecast – SUI Eyes $1.87 as Staking Move Fuels Breakout Rally
  • Bitcoin Price Prediction – Bulls Defend $80K as Rising Volume Points to $89K Target
  • Best Cryptocurrencies to Invest in Today, May 11 – Ethereum, Solana, Stellar
  • Capital B Raises €15.2M to Grow Its Bitcoin Holdings
  • Australia Plans Capital Gains Tax Changes That Could Affect Crypto Investors
  • South Korea to Crack Down on “Tether Laundromats” Used to Launder Stolen Money
  • Galaxy Says Stablecoins Could Add $1.2 Trillion in U.S. Credit by 2030
  • Toncoin Price Surges Over 90% in Seven Days — What Is Driving the TON Rally?
  • Court Approves Aave Recovery Plan for $71M Frozen in Lazarus-Linked KelpDAO Exploit