A decentralized exchange built on Uniswap V4 technology announced it will permanently close after an $8.4 million security breach drained its reserves, with the development team saying it lacks the funds needed to relaunch. Bunni DEX told users they can withdraw remaining assets, but the platform's treasury will be divided among token holders while the company winds down operations.
What to Know:
- Hackers exploited Bunni DEX's custom liquidity system on Sept. 2 using flash loans to manipulate calculations, draining funds across Ethereum and Unichain networks despite prior security audits.
- The platform's total value locked had surged from $2.2 million to nearly $80 million before the attack wiped out months of growth in seconds.
- The shutdown adds to a troubling year for decentralized finance, with more than $3.1 billion lost to exploits in 2025 according to security firm Hacken.
Exploit Details and Financial Fallout
The breach targeted Bunni's Liquidity Distribution Function, a proprietary mechanism the team developed to optimize trading liquidity. Attackers used flash loans—temporary, uncollateralized loans that must be repaid within the same blockchain transaction—to manipulate the platform's internal calculations. This triggered rounding errors that allowed the hackers to extract funds systematically.
Both Trail of Bits and Cyfrin had conducted security audits on Bunni's code before the attack. The logic-level vulnerability, however, went undetected by both firms.
The team halted all smart contracts immediately after discovering the breach.
They posted on X that relaunching the platform would require six to seven figures for comprehensive audits and monitoring systems. "To securely relaunch, we'd need six to seven figures for audits and monitoring, capital that we simply don't have," the team wrote.
Bunni's treasury will be distributed among holders of BUNNI, LIT, and veBUNNI tokens. The development team said it would exclude itself from any compensation payments. Users were told to withdraw their remaining assets "until further notice."
Before shutting down, the team relicensed its version 2 smart contracts from Business Source License to MIT. This opens the platform's technology—including liquidity distribution functions, surge fees, and autonomous rebalancing features—to other developers.
Industry Implications and Security Concerns
The platform's collapse underscores persistent vulnerabilities in decentralized finance protocols. Bunni had experienced rapid growth in the months before the attack, with data from DeFiLlama showing its total value locked climbing from $2.2 million to nearly $80 million. The breach eliminated that progress in seconds.
Flash loan attacks have become a recurring problem in decentralized finance. These exploits take advantage of the fact that blockchain transactions execute atomically—meaning all operations within a transaction either complete successfully or fail entirely. Attackers borrow large sums, manipulate prices or calculations, profit from the manipulation, repay the loan, and pocket the difference, all within a single transaction.
The $8.4 million loss at Bunni represents a fraction of the damage seen across the decentralized finance sector this year.
Security researchers at Hacken reported more than $3.1 billion in total losses from exploits in 2025.
The incident may prompt developers to reconsider how they deploy custom smart contract logic. Industry observers suggest platforms will likely increase spending on security audits, implement real-time monitoring systems, and expand bug bounty programs that pay researchers to identify vulnerabilities before attackers can exploit them.
Key Terms in Decentralized Finance
Total value locked refers to the amount of cryptocurrency deposited in a decentralized finance protocol, serving as a measure of the platform's size and user confidence. Flash loans are uncollateralized loans that must be borrowed and repaid within the same blockchain transaction, typically used for arbitrage but also exploited by attackers. Smart contracts are self-executing programs on blockchains that automatically enforce agreement terms without intermediaries.
Liquidity distribution functions manage how trading liquidity is allocated across different price ranges in a decentralized exchange, aiming to improve capital efficiency for both traders and liquidity providers.
Closing Thoughts
The Bunni DEX shutdown illustrates the financial and technical challenges facing decentralized finance platforms after major security breaches. The team's decision to open-source its technology before closing may allow other developers to learn from the platform's vulnerabilities while building future projects.

