{"investigation":{"slug":"zunami-protocol","entity_name":"Zunami Protocol","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Zunami Protocol is an Ethereum-based DeFi yield aggregator and stablecoin issuer (UZD, zETH) that suffered at least four separate security incidents between January 2023 and May 2025, losing a combined estimated $2.86 million or more in user funds. The protocol is notable for ignoring a prior warning from SlowMist before its largest smart contract exploit, and for a May 2025 incident in which an admin key compromise allegedly drained $500,000, with the team subsequently going silent for weeks and development activity having ceased months prior.","sections":[{"content":"Zunami Protocol is a decentralized finance (DeFi) yield aggregator launched on Ethereum that issued two synthetic assets: UZD (Zunami USD, an algorithmic stablecoin) and zETH (Zunami Ether). The protocol pooled user deposits into 'omnipools' spread across multiple yield strategies, primarily on Curve Finance, and marketed itself as offering the highest APY on the market. At its peak in mid-2023, Zunami reported approximately $5 million in total value locked (TVL). The protocol operated as a decentralized autonomous organization (DAO). Its smart contracts were audited by HashEx and Ackee Blockchain, though the exploited strategy (MIMCurveStakeDao) was reportedly added after initial audits were completed.","heading":"Protocol Overview","sources":[{"url":"https://decrypt.co/152366/zunami-protocol-curve-finance-hack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://hashex.org/audits/zunami-protocol/","name":"hashex.org","type":"other","credibility":3},{"url":"https://ackeeblockchain.com/blog/ackee-blockchain-audited-zunami-protocol/","name":"ackeeblockchain.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/zunami-protocol","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 26, 2023, a routine fund transfer by Zunami Protocol was sandwich-attacked in the mempool, resulting in an alleged loss of approximately $49,000. In February 2023, attackers used price gaps between Zunami's liquidity pools to repeatedly mint ZLP tokens at discounted prices and redeem them at inflated rates across thirteen transactions. Zunami's own Medium communications acknowledged total losses from this period of approximately $260,000. These early incidents established a pattern of exploitable vulnerabilities in the protocol's architecture.","heading":"January–February 2023 Exploits","sources":[{"url":"https://rekt.news/zunami-protocol-rekt2","name":"rekt.news","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/how-was-the-zunami-protocol-exploited-ea69a7a6a665","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On August 13–14, 2023, Zunami Protocol suffered its most publicized attack, a flash loan-enabled price manipulation exploit that drained approximately 1,184 ETH (approximately $2.1–2.16 million) from its stablecoin liquidity pools on Curve Finance. The attacker borrowed roughly $18.4 million in USDT, USDC, and WETH from Uniswap V3 and Balancer, then conducted strategic swaps on Sushiswap to artificially inflate the price of the StakeDAO (SDT) token. This manipulation caused the protocol's totalHoldings() function—which relied on Sushiswap pair prices without sufficient safeguards—to return inflated values. By calling cacheAssetPrice(), the attacker tripled their UZD balance from approximately 4.8 million to 16.9 million tokens before exiting at the inflated rate. Both UZD and zETH depegged catastrophically as a result: UZD fell over 99% and zETH fell over 88% to approximately $206. The stolen funds were laundered through the Tornado Cash mixer. The attack ranked as the 10th largest flash loan exploit of 2023 and represented the majority of August 2023's total flash loan losses across the DeFi ecosystem. Security firm PeckShield detected and reported the attack. Zunami confirmed the incident on its official channels and stated that underlying collateral remained secure, advising users not to purchase UZD or zETH during the attack. A critical aggravating factor was that blockchain security firm SlowMist had privately notified Zunami Protocol of the underlying vulnerability approximately two months before the exploit. According to SlowMist's founder, Zunami's response to that warning was described as 'an unpleasant communication,' and no remediation was performed.","heading":"August 2023 Price Manipulation Exploit ($2.1 Million)","sources":[{"url":"https://cointelegraph.com/news/zunami-protocol-confirms-stablecoin-pools-attacked-in-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/152366/zunami-protocol-curve-finance-hack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/3iea5hcDLs77TkOMQvoaSK-zunami-protocol-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-zunami-protocol-hack-august-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://rekt.news/zunami-protocol-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://neptunemutual.com/blog/how-was-the-zunami-protocol-exploited/","name":"neptunemutual.com","type":"other","credibility":3},{"url":"https://ackee.xyz/blog/zunami-hack-post-mortem/","name":"ackee.xyz","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/zunami-protocol-hack-aug-13-2023-detailed-analysis-report/","name":"immunebytes.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/zunami-protocol-exploited-for-over-2-million-native-stablecoin-uzd-plunges-99/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://beincrypto.com/hackers-stole-zunami-protocol/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In mid-May 2025, Zunami Protocol suffered a fourth major security incident, this time via an admin key compromise rather than a smart contract vulnerability. An entity with admin privileges called the withdrawStuckToken() function on Zunami's UsdtCrvUsdStakeDaoCurve strategy, transferring 296,456 LP tokens (collateral for zunUSD and zunETH) directly to an attacker-controlled wallet. The admin role was granted approximately seven minutes before the exploit was executed. PeckShield confirmed losses of approximately $500,000. The stolen funds were laundered through Tornado Cash. Prior to the exploit, Zunami's public GitHub repository had received no commits for at least three months, and the protocol's TVL had been declining steadily as yield incentives evaporated, suggesting development had been effectively abandoned while user funds remained locked. The protocol's CEO acknowledged they were 'considering both scenarios: a compromised deployer or malicious intent by the key holder.' The CTO claimed his laptop had been 'deeply investigated by Russian police' and alleged potential hard drive cloning. Following initial acknowledgments, the team allegedly went silent for approximately three weeks. A team moderator was reported to have stated they were located in Thailand and considered reporting the founder to Thai police. Rekt News reported the deployer wallet (0xe9b2B067eE106A6E518fB0552F3296d22b82b32B) as the address that initially granted the compromised admin access.","heading":"May 2025 Admin Key Compromise ($500,000)","sources":[{"url":"https://rekt.news/zunami-protocol-rekt2","name":"rekt.news","type":"other","credibility":3},{"url":"https://defillama.com/protocol/zunami-protocol","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"A particularly serious governance and operational risk factor is the allegation that Zunami Protocol was privately warned of the core price manipulation vulnerability exploited in August 2023 by SlowMist, a reputable blockchain security firm, approximately two months before the attack. SlowMist's founder described the team's response to this warning as 'an unpleasant communication.' The vulnerability was not patched. This indicates that even when a credible third party identified the specific flaw that would later result in $2.1 million in user losses, the Zunami team failed to act. The exploited MIMCurveStakeDao strategy was also reportedly introduced after the protocol's initial audits by HashEx and Ackee Blockchain were completed, meaning it did not undergo the same level of independent review as earlier code.","heading":"Ignored Security Warning (SlowMist)","sources":[{"url":"https://medium.com/neptune-mutual/how-was-the-zunami-protocol-exploited-ea69a7a6a665","name":"medium.com","type":"other","credibility":3},{"url":"https://neptunemutual.com/blog/how-was-the-zunami-protocol-exploited/","name":"neptunemutual.com","type":"other","credibility":3},{"url":"https://rekt.news/zunami-protocol-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://hashex.org/audits/zunami-protocol/","name":"hashex.org","type":"other","credibility":3}],"severity":"medium"},{"content":"Stolen funds from at least the August 2023 and May 2025 exploits were laundered through Tornado Cash, a cryptocurrency mixer sanctioned by the U.S. Office of Foreign Assets Control (OFAC) in August 2022. The use of Tornado Cash to launder proceeds from both incidents is consistent with the behavior of sophisticated actors seeking to obscure on-chain fund flows. No recovery of stolen funds has been publicly confirmed.","heading":"Funds Laundered via Tornado Cash","sources":[{"url":"https://rekt.news/zunami-protocol-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://rekt.news/zunami-protocol-rekt2","name":"rekt.news","type":"other","credibility":3},{"url":"https://cryptopotato.com/zunami-protocol-exploited-for-over-2-million-native-stablecoin-uzd-plunges-99/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Zunami Protocol's smart contracts were audited by HashEx (February 2023) and Ackee Blockchain prior to the August 2023 exploit. The HashEx audit of the UZD stablecoin component identified 8 issues: 0 Critical, 1 High, 0 Medium, 2 Low, and 5 Informational. However, the MIMCurveStakeDao strategy — the component exploited in August 2023 — was added after the completion of these audits and was not independently reviewed. A Zunami Protocol v2 re-audit was later conducted by Oxor. Despite multiple audits and at least one direct private disclosure of a critical vulnerability, the protocol experienced four separate exploits across roughly 28 months.","heading":"Audit History and Security Posture","sources":[{"url":"https://hashex.org/audits/zunami-protocol/","name":"hashex.org","type":"other","credibility":3},{"url":"https://hashex.org/audits/zunami-protocol-uzd/","name":"hashex.org","type":"other","credibility":3},{"url":"https://ackeeblockchain.com/blog/ackee-blockchain-audited-zunami-protocol/","name":"ackeeblockchain.com","type":"other","credibility":3},{"url":"https://ackeeblockchain.com/blog/zunami-uzd-audit-summary/","name":"ackeeblockchain.com","type":"other","credibility":3},{"url":"https://oxor-io.github.io/public_audits/Zunami/Zunami%20Protocol%20v2%20Reaudit%202%20Report.pdf","name":"oxor-io.github.io","type":"other","credibility":3},{"url":"https://zunamilab.gitbook.io/product-docs/risks-and-security/audits","name":"zunamilab.gitbook.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Zunami Protocol's founding team operated with a degree of anonymity that is not uncommon in the DeFi space but represents an elevated risk factor. Public disclosures do not clearly identify the founders by name. Following the May 2025 admin key exploit, the CEO and CTO made public statements through official channels. The CTO's claim of involvement by 'Russian police' in investigating his laptop, combined with a report of a team moderator allegedly located in Thailand threatening to report the founder to Thai police, suggests possible geographic distribution of team members across jurisdictions with limited crypto-specific enforcement. No independent verification of these claims is available. The protocol's LinkedIn presence exists but does not disclose individual team members.","heading":"Team Identity and Governance","sources":[{"url":"https://rekt.news/zunami-protocol-rekt2","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.linkedin.com/company/zunami-protocol","name":"linkedin.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of the time of this investigation, Zunami Protocol's TVL on DeFiLlama is reported at approximately $655,997, a dramatic decline from its 2023 peak. Development activity appears to have ceased prior to the May 2025 exploit based on GitHub commit history. The protocol has experienced four documented security incidents totaling an estimated $2.86 million or more in losses. No public recovery or compensation plan for the May 2025 exploit has been confirmed. The protocol's stablecoins UZD and zETH depegged catastrophically during the August 2023 attack and their current viability is uncertain. No regulatory actions by the SEC, CFTC, or other government bodies have been publicly filed against Zunami Protocol or its operators.","heading":"Current Status","sources":[{"url":"https://defillama.com/protocol/zunami-protocol","name":"defillama.com","type":"other","credibility":3},{"url":"https://rekt.news/zunami-protocol-rekt2","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-01-26","event":"Zunami Protocol's fund transfer is sandwich-attacked in the mempool; approximately $49,000 is lost.","source":""},{"date":"2023-02","event":"A series of 13 flash loan transactions exploit price gaps between Zunami liquidity pools; combined losses from January and February 2023 incidents totals approximately $260,000 per Zunami's own disclosure.","source":""},{"date":"2023-06","event":"SlowMist privately notifies Zunami Protocol of the price manipulation vulnerability that would later be exploited; team response is described as 'unpleasant' and no fix is applied.","source":""},{"date":"2023-08-13","event":"Zunami Protocol is exploited via a flash loan price manipulation attack targeting the MIMCurveStakeDao strategy; approximately $2.1 million (1,184 ETH) is drained from zETH and UZD pools on Curve Finance. UZD falls over 99% and zETH falls over 88%.","source":""},{"date":"2023-08-14","event":"Zunami confirms the exploit on social media; stolen funds are laundered via Tornado Cash. PeckShield, CertiK, Halborn, and Ackee Blockchain publish post-mortem analyses.","source":""},{"date":"2023-09","event":"Zunami Protocol completes an angel funding round and announces development of a V2 update.","source":""},{"date":"2025-05-14","event":"An admin key compromise results in the theft of approximately $500,000 in zunUSD and zunETH collateral. An admin role is granted 7 minutes before 296,456 LP tokens are transferred to an attacker wallet. Funds are laundered via Tornado Cash.","source":""},{"date":"2025-05","event":"Zunami team CEO and CTO make public statements; CTO alleges Russian police involvement and possible laptop cloning. Team subsequently goes silent for approximately three weeks. GitHub shows no commits for at least three months prior.","source":""}],"sources_used":[{"url":"https://decrypt.co/152366/zunami-protocol-curve-finance-hack","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260512002857/https://decrypt.co/152366/zunami-protocol-curve-finance-hack","credibility":3,"archive_timestamp":"2026-05-12T00:28:57+00:00"},{"url":"https://hashex.org/audits/zunami-protocol/","name":"hashex.org","type":"other","archive_url":"http://web.archive.org/web/20260421075955/https://hashex.org/audits/zunami-protocol/","credibility":3,"archive_timestamp":"2026-04-21T07:59:55+00:00"},{"url":"https://ackeeblockchain.com/blog/ackee-blockchain-audited-zunami-protocol/","name":"ackeeblockchain.com","type":"other","archive_url":"https://web.archive.org/web/20260829123543/https://ackee.xyz/blog/ackee-blockchain-audited-zunami-protocol/","credibility":3,"archive_timestamp":"2026-08-29T12:35:43+00:00"},{"url":"https://defillama.com/protocol/zunami-protocol","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20260421075934/https://defillama.com/protocol/zunami-protocol","credibility":3,"archive_timestamp":"2026-04-21T07:59:34+00:00"},{"url":"https://rekt.news/zunami-protocol-rekt2","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260513153556/https://rekt.news/zunami-protocol-rekt2","credibility":3,"archive_timestamp":"2026-05-13T15:35:56+00:00"},{"url":"https://medium.com/neptune-mutual/how-was-the-zunami-protocol-exploited-ea69a7a6a665","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/zunami-protocol-confirms-stablecoin-pools-attacked-in-exploit","name":"cointelegraph.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.certik.com/resources/blog/3iea5hcDLs77TkOMQvoaSK-zunami-protocol-incident-analysis","name":"certik.com","type":"other","archive_url":"https://web.archive.org/web/20260829145005/https://www.certik.com/blog/3iea5hcDLs77TkOMQvoaSK-zunami-protocol-incident-analysis","credibility":3,"archive_timestamp":"2026-08-29T14:50:05+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-zunami-protocol-hack-august-2023","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260516234400/https://www.halborn.com/blog/post/explained-the-zunami-protocol-hack-august-2023","credibility":3,"archive_timestamp":"2026-05-16T23:44:00+00:00"},{"url":"https://rekt.news/zunami-protocol-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260217113311/https://rekt.news/zunami-protocol-rekt","credibility":3,"archive_timestamp":"2026-02-17T11:33:11+00:00"},{"url":"https://neptunemutual.com/blog/how-was-the-zunami-protocol-exploited/","name":"neptunemutual.com","type":"other","archive_url":"http://web.archive.org/web/20251206043844/https://neptunemutual.com/blog/how-was-the-zunami-protocol-exploited/","credibility":3,"archive_timestamp":"2025-12-06T04:38:44+00:00"},{"url":"https://ackee.xyz/blog/zunami-hack-post-mortem/","name":"ackee.xyz","type":"other","archive_url":"https://web.archive.org/web/20260829181807/https://ackee.xyz/blog/zunami-hack-post-mortem/","credibility":3,"archive_timestamp":"2026-08-29T18:18:07+00:00"},{"url":"https://immunebytes.com/blog/zunami-protocol-hack-aug-13-2023-detailed-analysis-report/","name":"immunebytes.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cryptopotato.com/zunami-protocol-exploited-for-over-2-million-native-stablecoin-uzd-plunges-99/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260613001722/https://cryptopotato.com/zunami-protocol-exploited-for-over-2-million-native-stablecoin-uzd-plunges-99/","credibility":3,"archive_timestamp":"2026-06-13T00:17:22+00:00"},{"url":"https://beincrypto.com/hackers-stole-zunami-protocol/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260219002804/https://beincrypto.com/hackers-stole-zunami-protocol/","credibility":3,"archive_timestamp":"2026-02-19T00:28:04+00:00"},{"url":"https://hashex.org/audits/zunami-protocol-uzd/","name":"hashex.org","type":"other","archive_url":"http://web.archive.org/web/20260421075950/https://hashex.org/audits/zunami-protocol-uzd/","credibility":3,"archive_timestamp":"2026-04-21T07:59:50+00:00"},{"url":"https://ackeeblockchain.com/blog/zunami-uzd-audit-summary/","name":"ackeeblockchain.com","type":"other","archive_url":"https://web.archive.org/web/20260829123545/https://ackee.xyz/blog/zunami-uzd-audit-summary/","credibility":3,"archive_timestamp":"2026-08-29T12:35:45+00:00"},{"url":"https://oxor-io.github.io/public_audits/Zunami/Zunami%20Protocol%20v2%20Reaudit%202%20Report.pdf","name":"oxor-io.github.io","type":"other","archive_url":"http://web.archive.org/web/20260305153758/https://oxor-io.github.io/public_audits/Zunami/Zunami%20Protocol%20v2%20Reaudit%202%20Report.pdf","credibility":3,"archive_timestamp":"2026-03-05T15:37:58+00:00"},{"url":"https://zunamilab.gitbook.io/product-docs/risks-and-security/audits","name":"zunamilab.gitbook.io","type":"other","archive_url":"https://web.archive.org/web/20260830011606/https://zunamilab.gitbook.io/zunami-docs/product-docs/risks-and-security/audits","credibility":3,"archive_timestamp":"2026-08-30T01:16:06+00:00"},{"url":"https://www.linkedin.com/company/zunami-protocol","name":"linkedin.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:39.060386+00:00","updated_at":"2026-08-30T01:16:30.391692+00:00"}}