Highlights: Bunni lost $2.3 million in a smart contract exploit attack. The vulnerability came from its Liquidity Distribution Function. The exploiter moved funds to Aave, converting to stablecoins and ETH. Bunni, a decentralized exchange built on Ethereum and Uniswap V4, lost $2.3 million when a security breach let hackers take advantage of a flaw in its liquidity mechanism. The attack happened early on Tuesday, and Certik’s on-chain analysts immediately identified it. The attacker siphoned stablecoins, mostly USDC and USDT, from Bunni’s protocol. These assets were then sent through other decentralized finance (DeFi) platforms and finally deposited into Aave, a well-known lending platform that runs on Ethereum. According to the blockchain data, the wallet of the exploiter held $1.33 million of USDC and $1.04 million of USDT after the exploit. #CertiKInsight We have identified a $2.3M exploit on the @bunni_xyz BunniHub contract.https://t.co/lZB0vzSMQx The exploiter has exfiltrated funds to 0xe04efd87f410e260cf940a3bcb8bc61f33464f2b. Stay Vigilant! — CertiK Alert (@CertiKAlert) September 2, 2025 Liquidity Distribution Function Caused the Smart Contract Exploit At the center of the attack was a weakness in Bunni’s Liquidity Distribution Function (LDF). Bunni’s LDF is different from Uniswap’s default method because it tries to increase returns by moving liquidity around between different price ranges. This method was innovative, but it had a big flaw.  Security researchers exposed the attacker’s approach to exploiting this function, which involved trades of very specific sizes. These trades messed up the LDF’s rebalancing logic, which made a mistake when calculating the value of liquidity provider (LP) shares. This allowed the attacker to receive more tokens than they should have been able to. Victor Tran, the co-founder of KyberNetwork, said that the attacker “figured out they could manipulate the LDF by making trades of very specific sizes.” By doing these exact transactions over and over again, the exploiter was able to slowly take money without setting off any automated alarms. Furthermore, this smart contract exploit revealed a precision bug that could have arisen from a recent update to Bunni’s codebase. Despite the exploit, Bunnie had been audited previously. 1. Bunni is a liquidity hook that runs on top of UniswapV4. Instead of using UniswapV4’s normal system, Bunni has its own liquidity curve called LDF (Liquidity Distribution Function). 2. After each trade, Bunni checks if its LDF curve has changed since the last trade. If it has,… https://t.co/uCSWXyuAt2 — Victor Tran (@vutran54) September 2, 2025 Funds Routed Through Aave Following Exploit After successfully extracting funds from Bunni, the attacker transferred them via several DeFi protocols. Eventually, the stolen assets landed in Aave, which deposited them into lending pools, making tracing and recovery more difficult. Analysts were able to confirm that the attacker’s final wallet held large balances in Aave USDC and USDT assets. Shortly after the exploit was discovered, at 3:04 a.m., Bunni’s team posted a statement on X confirming the breach. The post reads: “The Bunni app has been compromised with a security exploit. For the safety of users, we have paused all smart contract functions on all networks.” Bunni engages with Euler Finance to handle some of its liquidity. However, Euler Labs CEO Michael Bentley explained that their protocol was not impacted by the exploit. He reassured users that none of the Euler systems were compromised during the incident. The timing of the attack was notable. Bunni had just surpassed $60 million in total value locked and more than $1 billion in trading volume in August. Immediately following the attack, BUNNI prices dropped more than 35% within an hour. Further research into the full extent of the exploit is still underway. This incident happened in the midst of a general increase in crypto-related hacks. Over $163 million was lost in 16 crypto-related incidents during the month of August alone. This was a 15% increase from the previous month. eToro Platform Best Crypto Exchange Over 90 top cryptos to trade Regulated by top-tier entities User-friendly trading app 30+ million users 9.9 Visit eToro eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong. Highlights: Bunni lost $2.3 million in a smart contract exploit attack. The vulnerability came from its Liquidity Distribution Function. The exploiter moved funds to Aave, converting to stablecoins and ETH. Bunni, a decentralized exchange built on Ethereum and Uniswap V4, lost $2.3 million when a security breach let hackers take advantage of a flaw in its liquidity mechanism. The attack happened early on Tuesday, and Certik’s on-chain analysts immediately identified it. The attacker siphoned stablecoins, mostly USDC and USDT, from Bunni’s protocol. These assets were then sent through other decentralized finance (DeFi) platforms and finally deposited into Aave, a well-known lending platform that runs on Ethereum. According to the blockchain data, the wallet of the exploiter held $1.33 million of USDC and $1.04 million of USDT after the exploit. #CertiKInsight We have identified a $2.3M exploit on the @bunni_xyz BunniHub contract.https://t.co/lZB0vzSMQx The exploiter has exfiltrated funds to 0xe04efd87f410e260cf940a3bcb8bc61f33464f2b. Stay Vigilant! — CertiK Alert (@CertiKAlert) September 2, 2025 Liquidity Distribution Function Caused the Smart Contract Exploit At the center of the attack was a weakness in Bunni’s Liquidity Distribution Function (LDF). Bunni’s LDF is different from Uniswap’s default method because it tries to increase returns by moving liquidity around between different price ranges. This method was innovative, but it had a big flaw.  Security researchers exposed the attacker’s approach to exploiting this function, which involved trades of very specific sizes. These trades messed up the LDF’s rebalancing logic, which made a mistake when calculating the value of liquidity provider (LP) shares. This allowed the attacker to receive more tokens than they should have been able to. Victor Tran, the co-founder of KyberNetwork, said that the attacker “figured out they could manipulate the LDF by making trades of very specific sizes.” By doing these exact transactions over and over again, the exploiter was able to slowly take money without setting off any automated alarms. Furthermore, this smart contract exploit revealed a precision bug that could have arisen from a recent update to Bunni’s codebase. Despite the exploit, Bunnie had been audited previously. 1. Bunni is a liquidity hook that runs on top of UniswapV4. Instead of using UniswapV4’s normal system, Bunni has its own liquidity curve called LDF (Liquidity Distribution Function). 2. After each trade, Bunni checks if its LDF curve has changed since the last trade. If it has,… https://t.co/uCSWXyuAt2 — Victor Tran (@vutran54) September 2, 2025 Funds Routed Through Aave Following Exploit After successfully extracting funds from Bunni, the attacker transferred them via several DeFi protocols. Eventually, the stolen assets landed in Aave, which deposited them into lending pools, making tracing and recovery more difficult. Analysts were able to confirm that the attacker’s final wallet held large balances in Aave USDC and USDT assets. Shortly after the exploit was discovered, at 3:04 a.m., Bunni’s team posted a statement on X confirming the breach. The post reads: “The Bunni app has been compromised with a security exploit. For the safety of users, we have paused all smart contract functions on all networks.” Bunni engages with Euler Finance to handle some of its liquidity. However, Euler Labs CEO Michael Bentley explained that their protocol was not impacted by the exploit. He reassured users that none of the Euler systems were compromised during the incident. The timing of the attack was notable. Bunni had just surpassed $60 million in total value locked and more than $1 billion in trading volume in August. Immediately following the attack, BUNNI prices dropped more than 35% within an hour. Further research into the full extent of the exploit is still underway. This incident happened in the midst of a general increase in crypto-related hacks. Over $163 million was lost in 16 crypto-related incidents during the month of August alone. This was a 15% increase from the previous month. eToro Platform Best Crypto Exchange Over 90 top cryptos to trade Regulated by top-tier entities User-friendly trading app 30+ million users 9.9 Visit eToro eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Bunni DEX Drained in $2.3M Smart Contract Exploit

3 min read

Highlights:

  • Bunni lost $2.3 million in a smart contract exploit attack.
  • The vulnerability came from its Liquidity Distribution Function.
  • The exploiter moved funds to Aave, converting to stablecoins and ETH.

Bunni, a decentralized exchange built on Ethereum and Uniswap V4, lost $2.3 million when a security breach let hackers take advantage of a flaw in its liquidity mechanism. The attack happened early on Tuesday, and Certik’s on-chain analysts immediately identified it.

The attacker siphoned stablecoins, mostly USDC and USDT, from Bunni’s protocol. These assets were then sent through other decentralized finance (DeFi) platforms and finally deposited into Aave, a well-known lending platform that runs on Ethereum. According to the blockchain data, the wallet of the exploiter held $1.33 million of USDC and $1.04 million of USDT after the exploit.

Liquidity Distribution Function Caused the Smart Contract Exploit

At the center of the attack was a weakness in Bunni’s Liquidity Distribution Function (LDF). Bunni’s LDF is different from Uniswap’s default method because it tries to increase returns by moving liquidity around between different price ranges. This method was innovative, but it had a big flaw. 

Security researchers exposed the attacker’s approach to exploiting this function, which involved trades of very specific sizes. These trades messed up the LDF’s rebalancing logic, which made a mistake when calculating the value of liquidity provider (LP) shares. This allowed the attacker to receive more tokens than they should have been able to.

Victor Tran, the co-founder of KyberNetwork, said that the attacker “figured out they could manipulate the LDF by making trades of very specific sizes.” By doing these exact transactions over and over again, the exploiter was able to slowly take money without setting off any automated alarms. Furthermore, this smart contract exploit revealed a precision bug that could have arisen from a recent update to Bunni’s codebase. Despite the exploit, Bunnie had been audited previously.

Funds Routed Through Aave Following Exploit

After successfully extracting funds from Bunni, the attacker transferred them via several DeFi protocols. Eventually, the stolen assets landed in Aave, which deposited them into lending pools, making tracing and recovery more difficult. Analysts were able to confirm that the attacker’s final wallet held large balances in Aave USDC and USDT assets. Shortly after the exploit was discovered, at 3:04 a.m., Bunni’s team posted a statement on X confirming the breach.

The post reads:

Bunni engages with Euler Finance to handle some of its liquidity. However, Euler Labs CEO Michael Bentley explained that their protocol was not impacted by the exploit. He reassured users that none of the Euler systems were compromised during the incident.

The timing of the attack was notable. Bunni had just surpassed $60 million in total value locked and more than $1 billion in trading volume in August. Immediately following the attack, BUNNI prices dropped more than 35% within an hour. Further research into the full extent of the exploit is still underway. This incident happened in the midst of a general increase in crypto-related hacks. Over $163 million was lost in 16 crypto-related incidents during the month of August alone. This was a 15% increase from the previous month.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Market Opportunity
MemeCore Logo
MemeCore Price(M)
$1.50466
$1.50466$1.50466
-0.79%
USD
MemeCore (M) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Best Crypto to Buy as Saylor & Crypto Execs Meet in US Treasury Council

Best Crypto to Buy as Saylor & Crypto Execs Meet in US Treasury Council

The post Best Crypto to Buy as Saylor & Crypto Execs Meet in US Treasury Council appeared on BitcoinEthereumNews.com. Michael Saylor and a group of crypto executives met in Washington, D.C. yesterday to push for the Strategic Bitcoin Reserve Bill (the BITCOIN Act), which would see the U.S. acquire up to 1M $BTC over five years. With Bitcoin being positioned yet again as a cornerstone of national monetary policy, many investors are turning their eyes to projects that lean into this narrative – altcoins, meme coins, and presales that could ride on the same wave. Read on for three of the best crypto projects that seem especially well‐suited to benefit from this macro shift:  Bitcoin Hyper, Best Wallet Token, and Remittix. These projects stand out for having a strong use case and high adoption potential, especially given the push for a U.S. Bitcoin reserve.   Why the Bitcoin Reserve Bill Matters for Crypto Markets The strategic Bitcoin Reserve Bill could mark a turning point for the U.S. approach to digital assets. The proposal would see America build a long-term Bitcoin reserve by acquiring up to one million $BTC over five years. To make this happen, lawmakers are exploring creative funding methods such as revaluing old gold certificates. The plan also leans on confiscated Bitcoin already held by the government, worth an estimated $15–20B. This isn’t just a headline for policy wonks. It signals that Bitcoin is moving from the margins into the core of financial strategy. Industry figures like Michael Saylor, Senator Cynthia Lummis, and Marathon Digital’s Fred Thiel are all backing the bill. They see Bitcoin not just as an investment, but as a hedge against systemic risks. For the wider crypto market, this opens the door for projects tied to Bitcoin and the infrastructure that supports it. 1. Bitcoin Hyper ($HYPER) – Turning Bitcoin Into More Than Just Digital Gold The U.S. may soon treat Bitcoin as…
Share
BitcoinEthereumNews2025/09/18 00:27
Breaking: CME Group Unveils Solana and XRP Options

Breaking: CME Group Unveils Solana and XRP Options

CME Group launches Solana and XRP options, expanding crypto offerings. SEC delays Solana and XRP ETF approvals, market awaits clarity. Strong institutional demand drives CME’s launch of crypto options contracts. In a bold move to broaden its cryptocurrency offerings, CME Group has officially launched options on Solana (SOL) and XRP futures. Available since October 13, 2025, these options will allow traders to hedge and manage exposure to two of the most widely traded digital assets in the market. The new contracts come in both full-size and micro-size formats, with expiration options available daily, monthly, and quarterly, providing flexibility for a diverse range of market participants. This expansion aligns with the rising demand for innovative products in the crypto space. Giovanni Vicioso, CME Group’s Global Head of Cryptocurrency Products, noted that the new options offer increased flexibility for traders, from institutions to active individual investors. The growing liquidity in Solana and XRP futures has made the introduction of these options a timely move to meet the needs of an expanding market. Also Read: Vitalik Buterin Reveals Ethereum’s Bold Plan to Stay Quantum-Secure and Simple! Rapid Growth in Solana and XRP Futures Trading CME Group’s decision to roll out options on Solana and XRP futures follows the substantial growth in these futures products. Since the launch of Solana futures in March 2025, more than 540,000 contracts, totaling $22.3 billion in notional value, have been traded. In August 2025, Solana futures set new records, with an average daily volume (ADV) of 9,000 contracts valued at $437.4 million. The average daily open interest (ADOI) hit 12,500 contracts, worth $895 million. Similarly, XRP futures, which launched in May 2025, have seen significant adoption, with over 370,000 contracts traded, totaling $16.2 billion. XRP futures also set records in August 2025, with an ADV of 6,600 contracts valued at $385 million and a record ADOI of 9,300 contracts, worth $942 million. Institutional Demand for Advanced Hedging Tools CME Group’s expansion into options is a direct response to growing institutional interest in sophisticated cryptocurrency products. Roman Makarov from Cumberland Options Trading at DRW highlighted the market demand for more varied crypto products, enabling more advanced risk management strategies. Joshua Lim from FalconX also noted that the new options products meet the increasing need for institutional hedging tools for assets like Solana and XRP, further cementing their role in the digital asset space. The launch of options on Solana and XRP futures marks another step toward the maturation of the cryptocurrency market, providing a broader range of tools for managing digital asset exposure. SEC’s Delay on Solana and XRP ETF Approvals While CME Group expands its offerings, the broader market is also watching the progress of Solana and XRP exchange-traded funds (ETFs). The U.S. Securities and Exchange Commission (SEC) has delayed its decisions on multiple crypto-related ETF filings, including those for Solana and XRP. Despite the delay, analysts anticipate approval may be on the horizon. This week, REX Shares and Osprey Funds are expected to launch an XRP ETF that will hold XRP directly and allocate at least 40% of its assets to other XRP-related ETFs. Despite the delays, some analysts believe that approval could come soon, fueling further interest in these assets. The delay by the SEC has left many crypto investors awaiting clarity, but approval of these ETFs could fuel further momentum in the Solana and XRP futures markets. Also Read: Tether CEO Breaks Silence on $117,000 Bitcoin Price – Market Reacts! The post Breaking: CME Group Unveils Solana and XRP Options appeared first on 36Crypto.
Share
Coinstats2025/09/18 02:35
Optimizely Named a Leader in the 2026 Gartner® Magic Quadrant™ for Personalization Engines

Optimizely Named a Leader in the 2026 Gartner® Magic Quadrant™ for Personalization Engines

Company recognized as a Leader for the second consecutive year NEW YORK, Feb. 5, 2026 /PRNewswire/ — Optimizely, the leading digital experience platform (DXP) provider
Share
AI Journal2026/02/06 00:47