Bunni V2 Hack
What happened
On September 2, 2025, Bunni DEX, a decentralized exchange built on Uniswap v4, suffered a multi-chain exploit that drained approximately $8.4 million in cryptocurrency. The attack targeted the BunniHub contract system with $2.3 million stolen on Ethereum and an additional ~$6.1 million from an earlier attack on Unichain, prompting the platform to pause all smart contract functions across networks.
The attacker exploited vulnerabilities in Bunni's custom Liquidity Distribution Function (LDF), which replaces Uniswap's standard logic to optimize returns for liquidity providers. By executing trades of very specific sizes, the exploiter manipulated the LDF curve and triggered faulty rebalancing calculations within the protocol's adaptive mechanisms. This caused the system to miscalculate liquidity provider share ownership, creating opportunities for gradual fund drainage.
The exploit specifically targeted how Bunni handles liquidity rebalancing across price ranges on its Uniswap v4-based infrastructure using the "hooks" feature. The attack occurred in two phases: an earlier exploit on Unichain network and a subsequent attack on Ethereum's mainnet targeting the BunniHub contract. Bunni's team immediately suspended all contract operations and urged users to withdraw funds while investigations continue.
Ethereum Exploit Transaction:
Unichain Exploit Transaction:
Attacker Wallets (Ethereum):
0xe04efd87…464f2b ($1.33M USDC, $1.04M USDT)
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report x.com
- analysis Website reference x.com
- analysis Website reference coinmarketcap.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.