Exploit Post Mortem
On September 2, Bunni was exploited for ~$8.4m by a sophisticated attacker. Two pools were affected: weETH/ETH on Unichain and USDC/USDT on Ethereum. The transactions can be found here: https://etherscan.io/tx/0x1c27c4d625429acfc0f97e466eda725fd09ebdc77550e529ba4cbdbc33beb97b https://uniscan.xyz/tx/0x4776f31156501dd456664cd3c91662ac8acc78358b9d4fd79337211eb6a1d451 Here is our analysis on how the exploit worked, what went wrong, and what we can do next. Exploit Analysis The two pools were exploited in largely the same way, and in this analysis we will use the USDC/USDT pool as the example. ...