The post Decentralized Exchange BunniXYZ Loses $8.4M in Liquidity Exploit appeared on BitcoinEthereumNews.com. In brief Decentralized exchange BunniXYZ has reportedly lost $8.4 million to a liquidity-based security exploit. The DEX has paused all smart contract activity on its network and is “actively investigating” the attack. Hackers reportedly manipulated Bunni’s “liquidity curve,” also known as its LDF, to carry out the exploit. Decentralized exchange (DEX) BunniXYZ has reportedly lost $8.4 million to a liquidity-based security exploit. According to on-chain security firm Hacken, $6 million of the DEX’s funds was stolen via the Unichain blockchain and $2.4 million via Ethereum. All Unichain funds were then bridged to Ethereum using the Across Protocol. Confirming the attack in a tweet, BunniXYZ said that it had paused all smart contract activity on its network and was “actively investigating” the circumstances of the attack. It added that it would provide updates soon. 🚨 The Bunni app has been affected by a security exploit. As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon. Thank you for your patience. — Bunni (@bunni_xyz) September 2, 2025 Founded in February 2025, BunniXYZ is based on automated market maker Uniswap v4, and primarily uses the Ethereum and Unichain blockchains. It currently has a cross-chain Total Value Locked (TVL) of just over $50 million according to DeFiLlama, though it exceeded $80 million at one point earlier this August. Michael Bentley, co-founder of lending protocol Euler, advised users to remove their funds from Bunni in a tweet, adding that while the DEX rebalances funds in and out of Euler, the lending protocol is “not affected or at risk.” Euler endured a major exploit of its own in 2023 that saw hackers steal nearly $200 million, the bulk of which was later recovered. What happened? According to on-chain analyst Victor Tran, co-founder of… The post Decentralized Exchange BunniXYZ Loses $8.4M in Liquidity Exploit appeared on BitcoinEthereumNews.com. In brief Decentralized exchange BunniXYZ has reportedly lost $8.4 million to a liquidity-based security exploit. The DEX has paused all smart contract activity on its network and is “actively investigating” the attack. Hackers reportedly manipulated Bunni’s “liquidity curve,” also known as its LDF, to carry out the exploit. Decentralized exchange (DEX) BunniXYZ has reportedly lost $8.4 million to a liquidity-based security exploit. According to on-chain security firm Hacken, $6 million of the DEX’s funds was stolen via the Unichain blockchain and $2.4 million via Ethereum. All Unichain funds were then bridged to Ethereum using the Across Protocol. Confirming the attack in a tweet, BunniXYZ said that it had paused all smart contract activity on its network and was “actively investigating” the circumstances of the attack. It added that it would provide updates soon. 🚨 The Bunni app has been affected by a security exploit. As a precaution, we have paused all smart contract functions on all networks. Our team is actively investigating and will provide updates soon. Thank you for your patience. — Bunni (@bunni_xyz) September 2, 2025 Founded in February 2025, BunniXYZ is based on automated market maker Uniswap v4, and primarily uses the Ethereum and Unichain blockchains. It currently has a cross-chain Total Value Locked (TVL) of just over $50 million according to DeFiLlama, though it exceeded $80 million at one point earlier this August. Michael Bentley, co-founder of lending protocol Euler, advised users to remove their funds from Bunni in a tweet, adding that while the DEX rebalances funds in and out of Euler, the lending protocol is “not affected or at risk.” Euler endured a major exploit of its own in 2023 that saw hackers steal nearly $200 million, the bulk of which was later recovered. What happened? According to on-chain analyst Victor Tran, co-founder of…

Decentralized Exchange BunniXYZ Loses $8.4M in Liquidity Exploit

2 min read

In brief

  • Decentralized exchange BunniXYZ has reportedly lost $8.4 million to a liquidity-based security exploit.
  • The DEX has paused all smart contract activity on its network and is “actively investigating” the attack.
  • Hackers reportedly manipulated Bunni’s “liquidity curve,” also known as its LDF, to carry out the exploit.

Decentralized exchange (DEX) BunniXYZ has reportedly lost $8.4 million to a liquidity-based security exploit.

According to on-chain security firm Hacken, $6 million of the DEX’s funds was stolen via the Unichain blockchain and $2.4 million via Ethereum. All Unichain funds were then bridged to Ethereum using the Across Protocol.

Confirming the attack in a tweet, BunniXYZ said that it had paused all smart contract activity on its network and was “actively investigating” the circumstances of the attack. It added that it would provide updates soon.

Founded in February 2025, BunniXYZ is based on automated market maker Uniswap v4, and primarily uses the Ethereum and Unichain blockchains. It currently has a cross-chain Total Value Locked (TVL) of just over $50 million according to DeFiLlama, though it exceeded $80 million at one point earlier this August.

Michael Bentley, co-founder of lending protocol Euler, advised users to remove their funds from Bunni in a tweet, adding that while the DEX rebalances funds in and out of Euler, the lending protocol is “not affected or at risk.” Euler endured a major exploit of its own in 2023 that saw hackers steal nearly $200 million, the bulk of which was later recovered.

What happened?

According to on-chain analyst Victor Tran, co-founder of Kyber Network, hackers manipulated Bunni’s “liquidity curve,” also known as its LDF (Liquidity Density Function). This is the system that calculates how much extra liquidity exists within the exchange and rebalances its liquidity pool to keep the right ratio of tokens.

Tran said hackers manipulated this LDF “by making trades of very specific sizes.” This caused the rebalancing calculation to break, producing incorrect results for how much each liquidity pool share should own.

By repeating this process, hackers allegedly withdrew more tokens than they should have been able to from Bunni.

Bunni itself has not yet confirmed the mechanism behind the attack.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source: https://decrypt.co/337673/decentralized-exchange-bunnixyz-loses-8-4m-in-liquidity-exploit

Market Opportunity
CROSS Logo
CROSS Price(CROSS)
$0.10758
$0.10758$0.10758
-1.16%
USD
CROSS (CROSS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP Ledger Unlocks Permissioned Domains With 91% Validator Backing

XRP Ledger Unlocks Permissioned Domains With 91% Validator Backing

XRP Ledger activated XLS-80 after 91% validator approval, enabling permissioned domains for credential-gated use on the public XRPL. The XRP Ledger has activated
Share
LiveBitcoinNews2026/02/06 13:00
Music body ICMP laments “wilful” theft of artists’ work

Music body ICMP laments “wilful” theft of artists’ work

The post Music body ICMP laments “wilful” theft of artists’ work appeared on BitcoinEthereumNews.com. A major music industry group, ICMP, has lamented the use of artists’ work by AI companies, calling them guilty of “wilful” copyright infringement, as the battle between the tech firms and the arts industry continues. The Brussels-based group known as the International Confederation of Music Publishers (ICMP) comprises major record labels and other music industry professionals. Their voice adds to many others within the arts industry that have expressed displeasure at AI firms for using their creative work to train their systems without permission. ICMP accuses AI firms of deliberate copyright infringement ICMP director general John Phelan told AFP that big tech firms and AI-specific companies were involved in what he termed “the largest copyright infringement exercise that has been seen.” He cited the likes of OpenAI, Suno, Udio, and Mistral as some of the culprits. The ICMP carried out an investigation for nearly two years to ascertain how generative AI firms were using material by creatives to enrich themselves. The Brussels-based group is one of a number of industry bodies that span across news media and publishing to target the fast-growing AI sector over its use of content without paying any royalties. Suno and Udio, who are AI music generators, can produce tracks with voices, melodies, and musical styles that echo those of the original artists such as the Beatles, Depeche Mode, Mariah Carey, and the Beach boys. “What is legal or illegal is how the technologies are used. That means the corporate decisions made by the chief executives of companies matter immensely and should comply with the law,” Phelan told AFP. “What we see is they are engaged in wilful, commercial-scale copyright infringement.” Phelan. In June last year, a US trade group, the Recording Industry Association of America, filed a lawsuit against Suno and Udio. However, an exception…
Share
BitcoinEthereumNews2025/09/18 04:41
XRPL Adds Institutional Lending and Privacy Tools in Ripple’s 2026 Roadmap

XRPL Adds Institutional Lending and Privacy Tools in Ripple’s 2026 Roadmap

Ripple shared a new Institutional DeFi roadmap showing how the XRP Ledger is being shaped for everyday use by banks, asset managers, and regulated financial firms
Share
Tronweekly2026/02/06 13:00