Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Bunni Reveals Code Flaw Behind $8.4 Million Exploit

The attacker exploited the rounding flaw with 44 small withdrawals, draining over 84% of the pool’s liquidity instead of evenly reducing balances.

Written By Dishita Malvania
Fact Checked by Dhara Chavda
Published 2025-09-05·Updated 1 year ago
Make The Crypto Times preferred on GoogleGoogle
Bunni Reveals Code Flaw Behind $8.4 Million Exploit

Decentralized exchange Bunni says a rounding bug in its smart contract was to blame for the $8.4 million exploit that struck earlier this week. In a post-mortem released on September 4, the team detailed how the attacker exploited the flaw to manipulate two liquidity pools and siphon off millions through a flash loan attack.

The exploit hit two pools: the weETH/ETH pair on Unichain and the USDC/USDT pair on Ethereum. 

How the Exploit Unfolded?

The attacker first flash-borrowed 3 million USDT, then carried out a series of swaps to push the pool’s spot price to an extreme level. This maneuver left the pool with only 28 wei of USDC in its active balance.

The real damage came next. The attacker carried out 44 tiny withdrawals, each one taking advantage of the contract’s rounding flaw. The assumption behind the design was that rounding would always go in a “safe” direction, rounding up the idle balance and rounding down the active one.

That logic may work for a single operation, but when repeated across multiple operations, it breaks down. By chaining withdrawals together, the attacker turned this “safe” rounding into a loophole, draining the pool’s active funds far beyond what was expected, wiping out more than 84% of its liquidity.

With the pool left exposed, the attacker made a big swap to push prices up, then quickly reversed the trade at the distorted rate to secure a large profit. Once the dust settled, the attacker walked away with roughly 1.33 million USDC and 1 million USDT, even after paying back the flash loan.

Why Some Pools Escaped?

Bunni noted that its largest pool, Unichain’s USDC/USD₮0, was left untouched, not because it was safer, but because the attacker couldn’t get the flashloan needed. According to Bunni, flash loan venues on Unichain didn’t have enough liquidity to push prices as required. In short, luck spared the pool.

The Flaw in the Code

The heart of the issue was a single assumption in Bunni’s withdrawal logic. Developers believed rounding balances down would protect the pool by making swaps more costly for traders. But when exploited repeatedly through tiny withdrawals, the opposite happened. Liquidity was understated to a dangerous degree, creating the opening for manipulation.

Bunni has since tested a fix by changing the rounding method, which neutralizes this specific attack. But the team admitted the incident exposed a gap in their testing framework and vowed to expand fuzz and invariant testing before resuming normal operations.

Next Steps and Recovery Efforts

The stolen funds are now sitting in two wallets tied to the attacker. Tracing efforts stalled after the funds were funneled through Tornado Cash, but Bunni said it has contacted the attacker with a proposal: return 90% of the stolen money and keep 10% as a “white-hat” reward. The team has also alerted centralized exchanges and engaged law enforcement.

Withdrawals have been reopened so liquidity providers can retrieve their assets, but deposits and swaps remain paused.

Despite the setback, Bunni’s six-person team insisted it would keep building. “We spent years of our lives and millions of dollars to launch Bunni, because we firmly believe it is the future of AMMs,” the team said in its closing note. “Regardless of what happens, we will continue to build Bunni and invent the future of DeFi.”

Also Read: Venus Recovers $13M After Phishing Attack Disrupts Protocol

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Decentralized Exchange
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Magic Eden Ethereum Flaw Whitehat 0xQuit Secures 3,832 NFTs, Users Told to Revoke Approvals
Magic Eden Ethereum Flaw: Whitehat 0xQuit Secures 3,832 NFTs, Users Told to Revoke Approvals
A physical gold Bitcoin coin in the foreground with the Sequans logo mounted on an office wall behind it.
Sequans Exits Bitcoin Treasury 15 Months After Setting 100,000 BTC Goal
Gracy Chen, CEO of Bitget
Bitget Hack Update: CEO Says Some Hacker Wallets Frozen, Withdrawals Still Paused; BGB Down 3.3%
A masked figure representing ZachXBT standing in front of a glowing Bitget logo.
Security Researcher ZachXBT Says ‘He Will Not Monitor’ Bitget Hack Incident 
Bryan Pellegrino, CEO of LayerZero, positioned between the Kelp DAO and LayerZero logos on a cracked background.
KelpDAO Sues LayerZero and CEO Bryan Pellegrino in Canada Over $292M rsETH Exploit

Find Us on Socials

You may also like

Bitget Hacked for $351.6M Withdrawals Frozen as CEO Points to North Korea

Bitget Hacked for $351.6M: Withdrawals Frozen as CEO Points to North Korea

Smartphone displaying Payy app logo on a bright lime-green screen held in hand

$1.83 Million in USDC Leaves Payy Network’s Ethereum Rollup Contract

Smartphone displaying Andreessen Horowitz a16z logo in front of the U.S. Securities and Exchange Commission seal

a16z Proposes Safe Harbor for DEXs Under SEC Exchange Rules

Sonic Cancels All Manual S Token Mints and Orders Independent Audit

Sonic Cancels All Manual S Token Mints and Orders Independent Audit

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information