Pundi AI Hack
What happened
On July 12, 2025, Pundi AI suffered a security exploit when a vulnerability in the PUNDIAI token swap contract was exploited through a front-running attack during deployment, resulting in unauthorized minting of approximately 1 million PUNDIAI tokens valued at around $6 million.
The attack targeted a vulnerability in the PUNDIAI token swap contract through a front-running attack executed during the contract deployment phase. This exploitation allowed the attacker to mint approximately 1 million unauthorized PUNDIAI tokens with an estimated value of $6 million at the time of the incident. Pundi AI detected the unauthorized activity and immediately initiated recovery operations, pausing all on-chain transfers of PUNDIAI tokens on both ERC20 and Pundi AIFX Omnilayer networks within three hours of detection.
The team coordinated with major exchanges including Upbit, Bithumb, Coinone, Gate.io, MEXC, and Coinex to implement asset freezes. Through these coordinated efforts, approximately 87% of the affected funds were successfully recovered, leaving a remaining loss of nearly $2 million that the project team committed to fully cover from their own resources. Pundi AI executed a 1:1 airdrop of new PUNDIAI tokens to ensure no users experienced losses.
Protocol details
Evidence
- report Report hacked.slowmist.io
- report Report gate.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.