PancakeBunny hack — May 2021
Incident facts
| Date of incident | |
|---|---|
| Target type | Other |
| Loss | $45,000,000Published estimates range $30,000,000 to $45,000,000Price at time of incident |
| Method | Oracle or price manipulationflash loans skewed the PancakeSwap V1 WBNB pool used by Bunny's PriceCalculatorBSCV1 to value LP tokens, inflating minted rewards |
| Chains | BNB Chain |
| Outcome | Users reimbursed |
What happened
PancakeBunny was a yield-aggregation protocol on BNB Chain. On 19 May 2021 at 22:34 UTC an attacker used a series of flash loans to distort the price feed the protocol used to value liquidity-provider tokens, minted about 6.97 million BUNNY as a performance-fee reward, and dumped it.
The flaw was in Bunny's PriceCalculatorBSCV1 contract, which valued a PancakeSwap LP token as twice the WBNB held in the pool. PeckShield traced flash loans of more than two million WBNB drawn from seven PancakeSwap pools plus 2.96 million USDT from Fortube Bank. The attacker swapped a large volume of WBNB into the thinly traded PancakeSwap V1 USDT/BNB pool, inflating its WBNB reserves and therefore Bunny's LP valuation and the reward it minted. After selling the new BUNNY and repaying the loans, the attacker retained 114,631 WBNB. BUNNY fell from roughly $145 to around $20 in the same session.
The dollar value of that balance is genuinely contested because BNB was crashing that day. PancakeBunny's own Go Forward Plan states that a hacker was able to gain about $45 million from the incident, and Decrypt reported $45 million from on-chain records; the auditor Christoph Michel's technical post-mortem values the same 114,631 WBNB at about $30 million. Headline claims of $200 million or $1 billion refer to the notional market value of the minted BUNNY, not to assets taken.
The team stressed that no vaults were breached. It issued pBUNNY against a compensation pool funded by protocol fees and team contributions, which repaid part of the loss. No one has been identified.
Sources
- Bunny Finance (PancakeBunny)Primary · retrieved 2026-08-01
- Christoph MichelSecondary · retrieved 2026-08-01
- PeckShieldSecondary · retrieved 2026-08-01
- DecryptSecondary · retrieved 2026-08-01
Official post-mortem: https://pancakebunny.medium.com/go-forward-plan-e29e58bc375f
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "PancakeBunny hack — May 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/pancakebunnyhttps://itokenly.com/hacks/pancakebunnyPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.