PancakeBunny Hack
What happened
On May 19, 2021, PancakeBunny's BNB Smart Chain yield vault was exploited through flash-loan-assisted manipulation of PancakeSwap liquidity and the protocol's LP-token valuation. The attacker made a small vault position, temporarily distorted relevant PancakeSwap reserves, and caused the reward path to treat a manipulated LP position as having far more value than the underlying performance fee. That inflated valuation allowed the attacker to mint 6,972,455 BUNNY, then sell BUNNY for WBNB before repaying the atomic borrowing.
The protocol said vault funds were not directly breached, but the excess minting collapsed BUNNY's market price and harmed token holders and liquidity providers.
PriceCalculatorBSCV1 derived LP value from instantaneous PancakeSwap reserves, while the minting path trusted that value. The flow also allowed removeLiquidity to consume the pair contract's whole LP balance rather than only LP tokens corresponding to the fee. Together, those assumptions let an atomic attacker manufacture a much larger apparent contribution and excess BUNNY rewards.
Case & protocol details
Attack Timeline
The attacker seeded a small VaultFlipToFlip position, then borrowed WBNB and USDT and left a large WBNB-USDT LP position in the pair contract. Calling getReward routed a tiny performance fee into BunnyMinter.mintForV2. The minter's liquidity-removal path consumed the pair contract's whole LP balance, including the attacker-controlled LP tokens.
It then priced the resulting BUNNY-WBNB position from manipulated spot reserves and minted BUNNY from the inflated value. The attacker sold the excess BUNNY and repaid the flash loans.
Funds Recovery
Recovered
$100K
Net Loss
$44,910,000
Evidence & learning
Sources and on-chain records
- report Post-mortem rekt.news
- report Report peckshield.medium.com
- report Report pancakebunny.medium.com
- transaction Transaction bscscan.com
- analysis PancakeBunny security update pancakebunny.medium.com
- analysis BSC PancakeBunny Exploit Post Mortem cmichel.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.