Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Litecoin Summit Day 1 Quantum Warnings, Privacy Coin Breakthroughs, & MiCA's Looming Deadline
    Litecoin Summit Day 1: Quantum Warnings, Privacy Coin Breakthroughs, & MiCA’s Looming Deadline
    Inside the High-Stakes Corporate War Over the GENIUS Act
    Inside the High-Stakes Corporate War Over the GENIUS Act
    From Demonetization to Digital Rupee India's Decade-Long Blockchain Journey
    From Demonetization to Digital Rupee: India’s Decade-Long Blockchain Journey
    The 7% Premium Trap Exposed How India Makes Crypto More Expensive Than Dollars
    The 7% Premium Trap Exposed: How India Makes Crypto More Expensive Than Dollars
    GENIUS Act Scorecard What US Regulators Have Done So Far
    GENIUS Act Scorecard: What US Regulators Have Actually Delivered
  • Opinion
    OpinionShow More
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Bunni Reveals Code Flaw Behind $8.4 Million Exploit

The attacker exploited the rounding flaw with 44 small withdrawals, draining over 84% of the pool’s liquidity instead of evenly reducing balances.

Written By Dishita Malvania Dishita Malvania
Fact Checked by Dhara Chavda Dhara Chavda
Published 2025-09-05·Updated 10 months ago
Make The Crypto Times preferred on GoogleGoogle
Last updated: September 5, 2025 2:17 PM
Published 2025-09-05
Share
Last updated: September 5, 2025 2:17 PM
Published 2025-09-05
Bunni Reveals Code Flaw Behind $8.4 Million Exploit

Decentralized exchange Bunni says a rounding bug in its smart contract was to blame for the $8.4 million exploit that struck earlier this week. In a post-mortem released on September 4, the team detailed how the attacker exploited the flaw to manipulate two liquidity pools and siphon off millions through a flash loan attack.

The exploit hit two pools: the weETH/ETH pair on Unichain and the USDC/USDT pair on Ethereum. 

How the Exploit Unfolded?

The attacker first flash-borrowed 3 million USDT, then carried out a series of swaps to push the pool’s spot price to an extreme level. This maneuver left the pool with only 28 wei of USDC in its active balance.

The real damage came next. The attacker carried out 44 tiny withdrawals, each one taking advantage of the contract’s rounding flaw. The assumption behind the design was that rounding would always go in a “safe” direction, rounding up the idle balance and rounding down the active one.

That logic may work for a single operation, but when repeated across multiple operations, it breaks down. By chaining withdrawals together, the attacker turned this “safe” rounding into a loophole, draining the pool’s active funds far beyond what was expected, wiping out more than 84% of its liquidity.

With the pool left exposed, the attacker made a big swap to push prices up, then quickly reversed the trade at the distorted rate to secure a large profit. Once the dust settled, the attacker walked away with roughly 1.33 million USDC and 1 million USDT, even after paying back the flash loan.

Why Some Pools Escaped?

Bunni noted that its largest pool, Unichain’s USDC/USD₮0, was left untouched, not because it was safer, but because the attacker couldn’t get the flashloan needed. According to Bunni, flash loan venues on Unichain didn’t have enough liquidity to push prices as required. In short, luck spared the pool.

The Flaw in the Code

The heart of the issue was a single assumption in Bunni’s withdrawal logic. Developers believed rounding balances down would protect the pool by making swaps more costly for traders. But when exploited repeatedly through tiny withdrawals, the opposite happened. Liquidity was understated to a dangerous degree, creating the opening for manipulation.

Bunni has since tested a fix by changing the rounding method, which neutralizes this specific attack. But the team admitted the incident exposed a gap in their testing framework and vowed to expand fuzz and invariant testing before resuming normal operations.

Next Steps and Recovery Efforts

The stolen funds are now sitting in two wallets tied to the attacker. Tracing efforts stalled after the funds were funneled through Tornado Cash, but Bunni said it has contacted the attacker with a proposal: return 90% of the stolen money and keep 10% as a “white-hat” reward. The team has also alerted centralized exchanges and engaged law enforcement.

Withdrawals have been reopened so liquidity providers can retrieve their assets, but deposits and swaps remain paused.

Despite the setback, Bunni’s six-person team insisted it would keep building. “We spent years of our lives and millions of dollars to launch Bunni, because we firmly believe it is the future of AMMs,” the team said in its closing note. “Regardless of what happens, we will continue to build Bunni and invent the future of DeFi.”

Also Read: Venus Recovers $13M After Phishing Attack Disrupts Protocol

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Decentralized Exchange
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Dishita Malvania
By Dishita Malvania
Follow:
Dishita Malvania is a Senior Crypto Journalist at The Crypto Times, based in Ahmedabad, India. She manages extensive daily news operations, tracking global digital asset trends, major international summits, market momentum, and localized exchange environments. Her investigative reporting covers India's evolving regulatory updates and enforcement actions, ensuring comprehensive documentation of regional market upheavals. Dishita holds a B.Tech degree in Computer Engineering, with an additional certification in Digital Media. Before joining The Crypto Times, she built a massive catalog of tech and media coverage. Her core reporting beats include crypto regulation and policy, blockchain security and cybercrime, AI in finance, Web3 infrastructure, and crypto fraud investigations and enforcement actions. Her three years of high-volume digital journalism have shaped her rapid fact-checking capabilities, source communication, and clear reporting style, making her work widely cited across premier global news outlets including Entrepreneur.com, The Independent, The Verge, and Metro.co.uk.
Dhara Chavda
By Dhara Chavda
Follow:
Dhara Chavda is a Research Analyst at The Crypto Times. She covers U.S. crypto regulation — including the CLARITY Act and GENIUS Act — DeFi security and major protocol exploits, and investigations into crypto fraud and enforcement actions. Her work emphasizes primary sourcing and on-chain verification over secondary commentary. Dhara joined The Crypto Times in 2020 and has followed every major market cycle since — the 2021 bull run, the 2022 Terra and FTX collapses, the 2023 banking turmoil, the 2024 spot Bitcoin ETF launch, and the 2025–2026 regulatory cycle — first assigning and reviewing the desk's coverage, and now writing it herself. Her reporting has been cited by international outlets including TheStreet and Argentina's La Nación. She holds a Bachelor of Engineering in Computer Engineering from Gujarat Technological University (GTU), which informs her technical reporting on on-chain data, smart contract analysis, and protocol architecture.

Latest News

Cardano Project SecondFi Halts Services as Hack Estimates Hit $20M
Cardano Project SecondFi Halts Services as Hack Estimates Hit $20M
U.S. House Sets July 17 Hearing on CLARITY Act’s Crypto Framework
U.S. House Sets July 17 Hearing on CLARITY Act’s Crypto Framework
ADA Price Slides Despite Cardano’s Biggest Scaling Test Yet
ADA Price Slides Despite Cardano’s Biggest Scaling Test Yet
80+ Advocates Urge Senate to Tighten CLARITY Act Safeguards
80+ Advocates Urge Senate to Tighten CLARITY Act Safeguards
Prince Group Hit With U.S. Sanctions in Crypto Fraud Crackdown
Prince Group Hit With U.S. Sanctions in Crypto Fraud Crackdown

Find Us on Socials

You may also like

Aave Founder Reacts as Goldfinch Shuts Down with $56M Frozen in Loans

Aave Founder Reacts as Goldfinch Shuts Down with $56M Frozen in Loans

THORChain Reopens 39 Days After $10.7M Exploit, Teases XMR & ZEC Swaps

THORChain Reopens 39 Days After $10.7M Exploit, Teases XMR & ZEC Swaps

Strategy’s STRC Stock Futures Goes Live on Hyperliquid Amid Volatile Comeback

Strategy’s STRC Stock Futures Goes Live on Hyperliquid Amid Volatile Comeback

Five Eyes Warns of AI Cyber Surge as Anthropic’s Fable 5 Ban Hits Crypto

Five Eyes Warns of AI Cyber Surge as Anthropic’s Fable 5 Ban Hits Crypto

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information