MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Bunni cites smart contract rounding error for $8.4 million flash loan exploit
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$69,096.00-0.77%
  • ethereumEthereum(ETH)$2,005.42-3.38%
  • tetherTether(USDT)$1.00-0.02%
  • rippleXRP(XRP)$1.524.23%
  • binancecoinBNB(BNB)$620.09-2.05%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$87.240.25%
  • tronTRON(TRX)$0.280156-1.11%
  • dogecoinDogecoin(DOGE)$0.1079696.35%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.32%
Blockchain Security

Bunni cites smart contract rounding error for $8.4 million flash loan exploit

Last updated: September 5, 2025 12:35 pm
Published: 5 months ago
Share

The lost $8.4 million has already been funneled through Tornado Cash, while Bunni is offering the attacker 10% of the stolen funds in exchange for returning the remainder.

Decentralized exchange Bunni published a post-mortem report on the exploit that resulted in $8.4 million in losses on Tuesday.

According to the report, the exploit affected two pools — the weETH/ETH pair on Unichain and the USDC/USDT pair on Ethereum mainnet.

Bunni identified an issue with the rounding direction in the smart contract for updating idle balances during withdrawals as the root cause of the exploit.

“The key to the exploit was the erroneous liquidity decrease resulting from the tiny withdrawals,” the report said. “It stemmed from this line in [BunniHubLogic::withdraw()] that handles the pool’s idle balance update.”

The attacker exploited this error to launch a flash loan attack that manipulated pool prices and liquidity, Bunni added.

First, they borrowed 3 million USDT via a flash loan and performed multiple swaps to manipulate the price, reducing the available USDC to just 28 wei. The attacker then exploited rounding errors with 44 small withdrawals, further draining the USDC balance and disproportionately dropping the pool’s total liquidity.

In the final step, the attacker executed a large swap to inflate the price tick and then performed a reverse swap at the manipulated price, the report said.

“To summarize, all of the rounding directions involved were safe in isolation, but when multiple operations are involved they led to an exploit,” said Bunni, adding that it has updated the rounding code to fix the vulnerability.

The platform has resumed withdrawals across all networks following fork testing by blockchain security firm Cyfrin, which confirmed their safety. However, deposits, swaps, and other functions remain paused.

“We are still exploring what fixes are needed to make Bunni secure again,” the platform said. “Changing the rounding direction of idle balance updates stops the current exploit, but it’s unclear if this change will introduce new attack vectors.”

The Bunni team said it traced the stolen funds to two wallets but could not identify the attacker as funds were funneled through crypto mixer Tornado Cash. Bunni is offering the attacker 10% of the funds as a bounty for returning the remainder, while also working with law enforcement and requesting centralized exchanges to freeze related accounts.

Looking ahead, Bunni said it will further develop its testing framework to fully restore the platform.

Read more on The Block

This news is powered by The Block The Block

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

DeFi November Nightmare: Crypto’s Critical Flaw Exposed
TAC InfoSec Targets USD 100M Revenue by 2030
Latest Ethereum News As Remittix Unveils CertiK KYC and Beta Wallet – Plus Updated Cardano Price Prediction – Cryptopolitan
Avalanche (AVAX) Price Prediction 2025: Can AVAX Hit $100 As Zero Knowledge Proof (ZKP) Whitelist Goes Live And The Next Crypto Megatrend Forms.
Hacker Drains Nearly $4M From Unleash Protocol, Funds Sent to Tornado Cash – FinanceFeeds

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Crypto’s Quantum Lockdown: What the SEC Just Did Next
Next Article DeFi Development Corp’s Solana treasury tops $400M following latest acquisition
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d