Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Ethereum exchange BunniXYZ drained for $2.3M in smart contract exploit

Ethereum exchange BunniXYZ drained for $2.3M in smart contract exploit

CryptopolitanCryptopolitan2025/09/02 10:50
By:By Hristina Vasileva

Share link:In this post: BunniXYZ was exploited through its liquidity rebalancing smart contract, moving $2.3M. The exploiter performed multiple transactions to use the smart contract bug, which performed flawed calculation and awarded more tokens. BunniXYZ had one of its most successful months in August, reaching peak TVL at over $60M.

The BunniXYZ Ethereum exchange saw a series of unauthorized outflows. On-chain investigators identified the event as a hack, with losses of around $2.3M. 

BunniXYZ, an Ethereum decentralized exchange, has been exploited through one of its smart contracts. The hacker moved mostly stablecoins, for a total loss of $2.3M. 

Based on the transaction history , the hacker attacked USDT and USDC vaults, then moved the tokens through the Ethereum ecosystem, ending up with a mix of ETH and stablecoins. Within the first minutes, the BunniXYZ project recognized the attack against its app, closing all smart contracts. 

Soon after the hack, the exploiter continued to swap funds into ETH through other DeFi protocols. 

In the hour after the attack, the hacker did not yet move or mix the funds, except for the initial movements through DeFi protocols. The attack against BunniXYZ is part of the latest series of relatively minor hacks, stealing less than $10M. 

Even the relatively small attacks often cost the reputation of protocols and destroy new DeFi hubs. One of the most recent smart contract exploits was against BetterBank, as Cryptopolitan reported . Such attacks raise suspicions of insider jobs, or malicious code injected into Web3 by DPRK hackers. 

See also Japan Post Bank plans to debut a blockchain-based digital yen by 2026

BunniXYZ attacked at the peak

BunniXYZ is a DEX using both Ethereum and Unichain. The new market also uses the Uniswap V4 technology to create special vaults and markets with more complex trading rules. 

As with other markets, BunniXYZ was attacked soon after reaching a local peak of value locked. At the end of August, the exchange carried up to $60M in its vaults. The market was still relatively small, after launching in February and finding its place among new DeFi protocols. 

August was also one of the most successful months for the DEX, with over $1B in volumes. The exchange was specifically building liquidity for rehypothecation , while avoiding liquidations during market downturns. The DEX liquidity was also linked to Euler Protocol for passive income.

BunniXYZ rode on the expanded volumes of Uniswap V4, as the protocol drew in over $393M to its vaults on Ethereum and $298M on Unichain.

Hacker exploited BunniXYZ liquidity calculation

Post-hack analysis showed BunniXYZ was vulnerable due to its specific liquidity recalculation contract. The DEX is a liquidity hook, using the Uniswap V4 technology. However, instead of using Uniswap’s liquidity calculation, BunniXYZ recalculates the Liquidity Distribution Function. 

The exploiter discovered the Liquidity Distribution Function could break from trades of specific sizes. This meant the smart contract would pay out more tokens from the liquidity pool than owned in reality, ending up draining the exchange. The attacker had to repeat multiple transactions to finally accrue $2.3M, then swap them out for ETH. He then ended up depositing the ETH into Aave, holding $1.33M in AethUSDC and $1M in AethUSDT based on the wallet’s final balance. 

See also Trump urges judge to block Lisa Cook’s bid to stay at Fed

BunniXYZ has undergone previous audits, but the LDF bug may have arrived with a later version of the exchange. The most probable cause is a precision bug, which required the hacker to perform multiple transactions to accrue a bigger balance based on the flawed recalculation.

If you're reading this, you’re already ahead. Stay there with our newsletter .

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Layer 2 Resilience and Investment Risk in Ethereum's Ecosystem

- Ethereum's L2 ecosystem faces operational risks as recent outages expose fragility in sequencer infrastructure and smart contract security. - Starknet's 2025 Grinta upgrade failure caused a 3-hour network freeze due to sequencer incompatibility, while Arbitrum and Base suffered outages from centralized sequencer vulnerabilities. - ZKsync's April 2025 airdrop exploit (111M tokens stolen) highlights critical security gaps, prompting price drops and exchange suspensions. - Investors must balance innovation

ainvest2025/09/02 18:00
Layer 2 Resilience and Investment Risk in Ethereum's Ecosystem

Stellar Network’s Protocol 23 Upgrade: A Strategic Catalyst for Institutional Adoption and Network Value Growth

- Stellar Network’s Protocol 23 upgrade (Sep 3, 2025) introduces CAP-0062-CAP-0068 and SEP-0041 to enhance scalability, smart contract efficiency, and institutional performance. - Features like parallel transaction execution (CAP-0063) and Soroban Live State Prioritization reduce costs and improve throughput, targeting 5,000 TPS for enterprise adoption. - Exchange pauses (e.g., Upbit) during the upgrade highlight Stellar’s institutional relevance, while optimized fees and compliance tools position it to co

ainvest2025/09/02 18:00
Stellar Network’s Protocol 23 Upgrade: A Strategic Catalyst for Institutional Adoption and Network Value Growth

MoonBull ($MOBU): The Whitelist Advantage and Why It Could Be the 1000x Crypto of 2025

- MoonBull ($MOBU)’s whitelist presale, with 80% spots filled by August 2025, leverages FOMO and Ethereum infrastructure to drive early adoption. - High APY staking rewards (66–80%) and a 30% liquidity pool aim to balance virality with sustainability, fostering community governance. - Ethereum Layer 2 scalability and institutional-grade audits reduce risks like rug pulls, appealing to both retail and institutional investors.

ainvest2025/09/02 18:00
MoonBull ($MOBU): The Whitelist Advantage and Why It Could Be the 1000x Crypto of 2025

The Structural Shift in Crypto: From Bitcoin to Ethereum as Whales and Macroeconomics Converge

- Crypto markets face structural shift as whales and macroeconomic trends drive capital from Bitcoin to Ethereum. - Bitcoin's dominance fell to 57.94% amid $2.7B sell-off, while Ethereum saw $2.5B accumulation and 46.9M on-chain transactions. - Regulatory clarity (GENIUS/CLARITY Acts) and Ethereum's Layer 2 innovations boost its appeal as a settlement and tokenized asset platform. - Institutional adoption and DeFi growth highlight Ethereum's utility over Bitcoin's "digital gold" narrative in evolving crypt

ainvest2025/09/02 18:00
The Structural Shift in Crypto: From Bitcoin to Ethereum as Whales and Macroeconomics Converge