Zunami Protocol Hack

TOTAL LOST $500K
Low Access Control Attacks ethereum

What happened

On May 15, 2025, Zunami Protocol suffered a $500,000 exploit involving the collateral backing its zunUSD and zunETH stablecoins. The attacker laundered the stolen funds via Tornado Cash, making recovery difficult.

Unlike previous incidents involving flash loans or price manipulation, this attack stemmed from compromised privileged access. The exploiter used admin-level permissions to withdraw and redeem protocol collateral directly, indicating a critical failure in access control. The ETH obtained from the redemption was swiftly transferred to Tornado Cash, obfuscating the attack trail.

The exploit, executed entirely at the protocol level, suggests either a severe internal security lapse or potential insider threat.

Case & protocol details

Classification Protocol Logic / Key Compromise / Yield Aggregator
Protocol Type Yield Aggregator
Smart Contract Language Solidity
Official Website www.zunami.io/
Protocol Twitter/X @ZunamiProtocol

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.