Skip to content
← Back to newsBunni DEX Halts Operations After $2.4 Million Liquidity Function Exploit
Markets

Bunni DEX Halts Operations After $2.4 Million Liquidity Function Exploit

By BishopNewcomer0 rep· 9/2/2025

Decentralized exchange Bunni has temporarily paused all smart contract functions across all networks following a significant security exploit that resulted in the loss of approximately $2.4 million in stablecoins. Attackers reportedly manipulated the platform's custom liquidity rebalancing mechanism, leading to the draining of funds.

Key Takeaways

  • Bunni DEX paused operations after a $2.4 million exploit.

  • The attack targeted the platform's custom Liquidity Distribution Function (LDF).

  • Funds were drained through manipulated rebalancing calculations.

The Exploit Unfolds

Bunni, which is built on Uniswap v4, utilizes a proprietary Liquidity Distribution Function (LDF) instead of Uniswap's default logic. This custom feature is designed to optimize liquidity allocation across various price ranges, aiming to enhance returns for liquidity providers. However, early analysis suggests a flaw within this LDF allowed attackers to manipulate its curve.

According to reports, attackers were able to execute trades of very specific sizes. These carefully chosen trade amounts reportedly caused the LDF's rebalancing calculations to malfunction, resulting in incorrect valuations of liquidity provider shares. This allowed the attacker to gradually drain the protocol's funds over multiple transactions without immediately triggering alarms.

The stolen funds consisted of $1.33 million in USDC and $1.04 million in USDT, which were transferred to a single address. In response to the incident, a core contributor for Bunni urged users to withdraw their funds from the platform as quickly as possible.

Broader Context of Crypto Hacks

This incident occurs amidst a broader trend of increasing crypto hacks. In August alone, crypto hackers and scammers reportedly stole over $163 million across 16 separate incidents. While this figure is lower year-over-year, it indicates a rise in targeted attacks as the crypto market gains momentum. Cybersecurity experts have noted a strategic shift, with attackers increasingly focusing on centralized exchanges and high-value individuals rather than smaller, decentralized targets. A notable August incident involved a social engineering attack where a Bitcoin holder lost 783 BTC, valued at $91 million, after being tricked by individuals posing as exchange and hardware wallet support agents.

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Bunni DEX Halts Operations After $2.4 Million Liquidity Function Exploit | BlockzHub