The decentralized finance (DeFi) ecosystem was shaken by two consecutive attacks on September 2nd. Venus Protocol, which operates on the BNB Chain, lost approximately $27 million, while Bunni, an Ethereum-based decentralized exchange, lost $8.4 million, according to updated data.
Venus Protocol Loss $27 Million
According to on-chain analysis, the attackers updated Venus Protocol's Core Pool Comptroller contract to a malicious address. This transferred the protocol's tokens, such as vUSDC and vETH, to the attacker-controlled address.
The stolen funds are currently sitting in the attacker's wallet and have not yet been converted into other assets. Security teams are closely monitoring the movement of the funds. No official statement has been released by the protocol team or the community.
Venus Protocol is one of BNB Chain's largest money markets, where users can earn interest by depositing stablecoins and major crypto assets and obtain loans against collateral. Its native token, XVS, plays a role in governance and incentives. Following the attack, the XVS price fell to $6, losing over 5% on a daily basis.
Bunni suffered an $8.4 million hack
The second attack of the day targeted the Ethereum-based decentralized exchange Bunni. While initial reports indicated a loss of $2.3 million, later updated data indicated that the total loss reached $8.4 million.
The attacker exploited a vulnerability in Bunni's liquidity distribution function (LDF) to manipulate contract calculations. This method resulted in excessive withdrawals from the protocol, bringing the funds under the attacker's control. The withdrawn assets were reportedly moved between the Ethereum and Unichain networks.
Following the incident, the Bunni team announced that it had halted all smart contracts as a security precaution. Following the attack, the Bunni token price plummeted, losing more than 30% of its value to $0.0015. We can summarize the current situation as follows:
Protocol
Loss Amount
Attack Method
Current Status
Venus Protocol
$27 million
Comptroller contract update
Funds in attacker wallet, no official statement
Bunni
$8.4 million
Error in liquidity distribution function
Smart contracts suspended, investigation ongoing