Résumé
On 20 May 2021 PancakeBunny, a yield aggregator on BNB Chain, was drained of roughly $45 million (about 114,000 WBNB plus around 3.8M USDT) in a flash-loan mint-manipulation attack that crashed the BUNNY token by over 95%. The protocol's reward minting valued assets through a price calculator that read the spot reserves (getReserves) of the BUNNY/WBNB and USDT/WBNB PancakeSwap pairs, and computed LP amounts with raw balanceOf() that could be inflated by direct transfers. The attacker took recursive flash loans of millions of WBNB, swapped WBNB for USDT to cheapen WBNB and skew both pools, then triggered the deposit/reward path so the manipulated price fed the BUNNY mint formula (amplified by a multiplier) and minted roughly 6.9 million BUNNY from nothing, which they immediately dumped into the inflated pool for WBNB and USDT. The root cause was computing mint amounts from manipulable on-chain spot reserves and unguarded balanceOf() rather than an external price.
Comment l’éviter dans votre code
- Never derive mint or reward amounts from a pool's getReserves()/balanceOf() spot price; use an external oracle
- Adopt Chainlink or a long-window TWAP for asset valuation in minting math
- Do not trust balanceOf() deltas for LP accounting; track amounts internally so direct transfers cannot inflate them
- Cap or rate-limit mint output per transaction and reject when computed value diverges from a reference price
- Assume flash loans can skew any single-pool price within the call; block atomic deposit-then-mint-then-dump flows
Références
- https://medium.com/amber-group/bsc-flash-loan-attack-pancakebunny-3361b6d814fd
- https://www.halborn.com/blog/post/explained-the-pancakebunny-protocol-hack-may-2021
- https://www.coindesk.com/markets/2021/05/20/flash-loan-attack-causes-defi-token-bunny-to-crash-over-95
- https://cointelegraph.com/news/pancakebunny-tanks-96-following-200m-flash-loan-exploit
Vulnérabilités liées
Tout Web3 →- CRITICALWEB3-CREAM-FINANCE-2021
On October 27, 2021, lending protocol Cream Finance was drained of about $130 million in its third and largest exploit of the year. Using two coordinated addresses, the attacker took flash loans of roughly 500M DAI from MakerDAO and about $2B in ETH from Aave. They then manipulated the price-per-share oracle for Cream's yUSDVault (crYUSD) collateral: that price was computed as the vault's yUSD balance divided by yUSDVault totalSupply, so by redeeming roughly $500M of vault tokens they shrank totalSupply to about $8M while keeping vault value high, then donating/depositing ~$8M yUSD into the vault. This roughly doubled the perceived per-share value, so Cream valued the attacker's crYUSD collateral at about $3B instead of ~$1.5B, letting them borrow and drain the lending pools. The exploit wallet was funded via Tornado Cash about 30 minutes earlier. The attacker was never identified and the funds were not recovered.
- CRITICALWEB3-VALUEDEFI-2020
On 14 November 2020 Value DeFi's MultiStables vault was exploited for a net loss of roughly $6 million on Ethereum (the attacker later returned some funds) in a flash-loan price-manipulation attack, despite the vault marketing itself as flash-loan resistant. The vault valued stablecoin shares by converting assets to USDC and pricing them against Curve's 3pool spot rates, with no protection against intra-block manipulation, and deposits were not gated against contracts. The attacker flash-borrowed 80,000 ETH from Aave plus a large DAI flash swap from Uniswap, deposited DAI to mint vault shares, then swapped tens of millions of DAI and USDT into USDC to drain USDC from the 3pool so the remaining conversion returned inflated 3CRV amounts, making the vault's share price read about 1.32x its true value. They then withdrew their shares for far more 3CRV than deposited and repaid the loans for profit. The root cause was share pricing off a single Curve pool's manipulable spot rate inside one transaction.
- CRITICALWEB3-KELPDAO-LAYERZERO-2026
On April 18, 2026, North Korea's Lazarus Group drained about 116,500 rsETH (roughly $292 million) from KelpDAO's LayerZero-based bridge, the largest DeFi exploit of the year. No smart contract was broken; the contracts did exactly what they were written to do. The attack was against the bridge's off-chain verification. rsETH's LayerZero channel was configured to trust a single verifier (a 1-of-1 DVN), so the attackers compromised LayerZero's internal RPC nodes, knocked out the honest external node with a denial-of-service flood, and forced that single verifier to attest to a cross-chain message that never really happened. The Ethereum side then released unbacked rsETH from escrow, leaving wrapped rsETH stranded across more than twenty chains and triggering a bank-run across DeFi.
- HIGHWEB3-FRONTEND-DNS-HIJACK-2022
A frontend hijack leaves the on-chain contracts untouched but replaces the Web2 surface serving the dApp UI with a wallet-drainer clone, so no Solidity audit can catch it. The recurring pattern: attackers take over the domain registrar or DNS provider account (or a CDN/tag-manager account), repoint the domain to a cloned site, and prompt visitors to sign malicious token approvals, EIP-2612 permit signatures, or transfers. Curve Finance was hit twice: on August 9-10, 2022 its curve.fi domain was DNS-hijacked via a compromised nameserver and drained ~$570K in USDC/DAI; and again around May 12, 2025 at the registrar level, after which Curve permanently migrated to curve.finance and announced an ENS move (Convex Finance and Resupply, which depend on Curve's data feeds, suffered dependency-driven outages but were not themselves compromised). In July 2024 a mass wave hit DeFi domains registered through Squarespace, whose forced migration off Google Domains stripped 2FA: Compound's frontend redirected to an Inferno Drainer clone and 100+ protocols were exposed (Celer blocked its takeover via domain monitoring). Ambient Finance's domain was hijacked through stolen registrar credentials on October 17, 2024. Most recently, on April 14, 2026 attackers used forged identity documents to social-engineer the registrar into handing over DNS control of CoW Swap's swap.cow.fi and cow.fi domains, redirecting users to a pixel-perfect drainer clone for about 90 minutes; over $1M was taken in roughly three hours, including 219 ETH (~$750K) from a single wallet, while CoW's contracts, backend APIs, and solver network were untouched. The same bucket includes CDN-account injections (KyberSwap's September 2022 Cloudflare/Google Tag Manager compromise, ~$265K) and BGP route hijacks that swap signed bundles for drainer code.
- CRITICALWEB3-BUNNI-2025
On September 2, 2025 Bunni, a liquidity manager built on Uniswap v4, was drained of roughly $8.4 million across Ethereum and Unichain (USDC, USDT, and weETH/ETH) through a rounding error in its withdrawal accounting amplified by flash loans. Bunni's Liquidity Distribution Function (LDF) tracks an 'idle balance' that is rebalanced on every swap, and the withdraw path rounded that balance in the wrong direction under specific conditions. The attacker flash-borrowed millions in USDT and executed a precisely sized sequence of swaps that pushed the pool's spot price back and forth across tick boundaries, triggering the faulty rounding repeatedly; each cycle let them withdraw more tokens than they burned in liquidity (in the USDC/USDT pool the idle balance fell 85.7% while liquidity fell only 84.4%, and that gap was the leak). The bug was application-specific accounting math, not an oracle or price-feed flaw. Unable to fund a secure relaunch, the Bunni team announced on October 23, 2025 that it was permanently shutting down, leaving withdrawals open and relicensing v2 from BUSL to MIT.
- CRITICALWEB3-CETUS-SUI-2025
On 22 May 2025, Cetus Protocol, the largest decentralized exchange on the Sui blockchain, was drained of about $223 million in the time it takes to read this sentence. The attacker did not steal a key or trick a signer. They found a single wrong constant in an overflow check, buried not in Cetus's own code but in a shared open-source math library, integer-mate, that Cetus and several other Sui projects all depended on. With a one-token deposit and a flash loan, they convinced the protocol that a position worth almost nothing was worth a fortune, then withdrew the real reserves. It is the cleanest modern example of a vulnerability in a dependency draining the protocols built on top of it, and the second largest crypto theft of 2025 after Bybit.