• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Bunni Suffers $8.4 Million Loss Due to Security Exploit on Ethereum and Unichain
Share
  • bitcoinBitcoin(BTC)$64,158.00
  • ethereumEthereum(ETH)$1,732.50
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$591.18
  • usd-coinUSDC(USDC)$1.00
  • rippleXRP(XRP)$1.14
  • solanaSolana(SOL)$74.21
  • tronTRON(TRX)$0.327381
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
  • HyperliquidHyperliquid(HYPE)$68.17
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
DeFi

Bunni Suffers $8.4 Million Loss Due to Security Exploit on Ethereum and Unichain

News Desk
Last updated: September 4, 2025 2:13 am
News Desk
Published: September 4, 2025
Share
BunniProtocolExploited

A major security breach has hit the decentralized exchange protocol Bunni, resulting in a staggering loss of $8.4 million. The exploit was identified by multiple blockchain security firms, revealing a precision bug in the platform’s liquidity distribution function that allowed hackers to drain funds from liquidity pools on Ethereum and Unichain.

Bunni’s core team acted quickly following the identification of the exploit. In a communication on social media, they confirmed that they had paused all smart contract functions across every supported network as a precautionary measure. They assured their users that an investigation was underway and promised to provide updates in the near future.

The incident first came to light when the audit firm BlockSec flagged transactions that appeared suspicious, involving around $2.3 million on Ethereum. Bunni responded within two hours to confirm that a breach had occurred. Further analysis conducted by Hacken revealed an additional loss of approximately $6 million on Unichain, further amplifying the total stolen funds to $8.4 million. The compromised assets are believed to be held in two wallets linked to the attacker.

According to Victor Tran, CEO of KyberSwap, the vulnerability was rooted in a flaw within Bunni’s liquidity distribution function curve. The attacker executed trades with highly specific sizes, effectively manipulating the rebalancing calculation and leading to incorrect allocations of liquidity provider shares. This manipulation allowed the hacker to withdraw excess LP tokens, systematically emptying Bunni’s liquidity reserves in the process.

Despite previously undergoing security audits by reputable firms, including Trail of Bits and Cyfrin, the situation raises critical questions regarding the robustness of ongoing code reviews and the overall security of decentralized finance platforms. It remains uncertain whether the exploited bug had been identified during past audits or if it had been introduced at a later stage.

The attacker’s activities produced over 1,000 event logs, with some containing comments such as “Depositing to Euler” and “Unlock Callback,” which offer investigators potential leads into the execution of this exploit.

In the broader security context of decentralized finance, the incident has reverberated within the community. Euler co-founder Michael Bentley stated that while Bunni manages the rebalancing of funds with Euler, the $1.5 billion lending protocol remained unaffected by this breach. This comes in the wake of Euler’s own hacking incident in March 2023, where the platform lost $200 million, emphasizing the ongoing vulnerabilities faced by DeFi platforms. As such, the Bunni exploit serves as yet another reminder of the critical need for rigorous, ongoing security assessments within the space.

OKX Launches USDT0 on Layer 2 X Layer, Revolutionizing Stablecoin Interoperability
Bithumb Partners with Trump-Affiliated World Liberty Financial to Boost DeFi Growth
New DeFi Protocol BNBCapital Promises Up to 17% Daily ROI with Audited Security
Low-risk DeFi: Balancing Revenue and Principles in the Ethereum Community
SEC and CFTC to Host Public Roundtable on Crypto Regulation on September 29
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article Screenshot 2025 09 02 at 09 32 36 XRP Price Slides Below 2 Google Docs BRICS Economic Report Highlights XRP Ledger’s Role in Trade Finance Solutions
Next Article aud usd 001 Large USD/JPY Capped Below 148.50 Ahead of Key Jobs Data
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8740832F23 06 28 the words safety first wit
Preparing Your Wish List for High-Quality Stocks in a Potential Bear Market
anthropic claude fable
Anthropic’s AI Models Taken Offline Amid Trump Administration’s Export Controls, Sparking Debate on AI Policy
1760632538 news story
Bitcoin’s Market Divided: Demand Rises, But Resistance Caps Recovery
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • Bitcoin
  • News
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?