Bunni V2 hack — September 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 2, 2025 |
| Target type | Decentralised exchange |
| Loss | $8,400,000Published estimates range $8,300,000 to $8,400,000Price at time of incident |
| Method | Contract logic errorRounding-direction bug in BunniHubLogic::withdraw. Idle balances were rounded down using mulDiv, which was safe in isolation but compounded across many small withdrawals, letting the attacker cut a pool's active liquidity far more than the liquidity shares burned justified. Flash loans and sandwich swaps were used to set up and monetise the distortion. |
| Chains | Ethereum, Other |
| Outcome | Project shut down |
What happened
On 2 September 2025 an attacker exploited a rounding bug in Bunni V2, a liquidity manager built as a hook on Uniswap V4, draining the USDC/USDT pool on Ethereum and the weETH/ETH pool on Unichain.
Bunni's post-mortem, published two days later, identifies the root cause as the rounding direction used when updating idle balances inside BunniHubLogic::withdraw. The code rounded down, which the team described as safe for any single operation but exploitable when chained. The attacker flash-borrowed 3 million USDT and swapped it to push the pool's price tick to an extreme value, reducing the active USDC balance to 28 wei. They then made 44 tiny withdrawals that compounded the rounding error, cutting the USDC active balance by 85.7% and total pool liquidity by 84.4% while burning almost no liquidity shares. A large reversing swap then restored the artificial liquidity, and the attacker sandwiched subsequent swaps at the distorted prices. Bunni reported the net profit after flash-loan repayment as roughly 1.33 million USDC and 1 million USDT on the Ethereum leg.
Reported totals are close: The Block, Decrypt and CoinDesk all cite about $8.4 million, while QuillAudits' breakdown of $2.4 million on Ethereum and $5.9 million on Unichain gives $8.3 million.
Bunni paused deposits and swaps, reopened withdrawals after testing by Cyfrin, offered the attacker a 10% bounty, contacted exchanges and engaged law enforcement. The funds were bridged to Ethereum and left in wallets funded through Tornado Cash. On 23 October 2025 Bunni announced it was shutting down, saying a secure relaunch would cost six to seven figures in audits and monitoring it no longer had, and relicensed its V2 contracts from BUSL to MIT.
Sources
- BunniPrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- DecryptSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- QuillAuditsSecondary · retrieved 2026-08-01
Official post-mortem: https://blog.bunni.xyz/posts/exploit-post-mortem/
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Bunni V2 hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bunni-v2https://itokenly.com/hacks/bunni-v2Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.