Skip to main content
AVOID.NET
Bunni Protocolreviewed 2026-09-09 · 30 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Bunni Protocol against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

partially supported 3confirmed 270 corrections pending · 0 applied

partially supported

3 claims

The cited evidence supports part of the claim but not all of it.

  1. #17[partially supported][awaiting moderator]in the timeline
    2025
    reviewerTrail of Bits audit occurred in 2025 (timeline date field), flagging TOB-BUNNI-13 and TOB-BUNNI-9The timeline date field is underspecified (year-only) even though the page's own section content and date_original both pin this to January 2025; the field should carry the same precision available elsewhere on the page.
  2. #20[partially supported][awaiting moderator]in section: Audit History and Pre-Exploit Warnings
    Despite these recommendations, Bunni's TVL surged from roughly $2.4 million to $23.9 million in the immediate aftermath of the June 2025 Cyfrin audit, indicating that growth was prioritized over the auditors' cautionary guidance.
    reviewerBunni's TVL surged from roughly $2.4 million to $23.9 million in the immediate aftermath of the June 2025 Cyfrin auditThe dollar figures and general causal narrative (growth despite auditor warnings) are correct, but 'in the immediate aftermath' overstates the timing; the surge occurred about seven weeks after publication, not immediately.
  3. #21[partially supported][awaiting moderator]in the timeline
    Cyfrin audit identifies 50+ issues and warns that 'complex bugs still present' are statistically likely, advising against further scaling without additional security work. TVL surges from $2.4M to $23.9M immediately after publication.
    reviewerCyfrin audit identifies 50+ issues; TVL surges from $2.4M to $23.9M immediately after publicationSame underlying timing overstatement as the Audit History section; grouped under the same defect_group.

confirmed

27 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Protocol Overview
    Bunni was created by Timeless Finance, a DeFi development group led pseudonymously by Zefram Lou (GitHub: ZeframLou, handle: boredGenius / zefram.eth).
    reviewerBunni was created by Timeless Finance, led pseudonymously by Zefram Lou (GitHub: ZeframLou, handle boredGenius / zefram.eth)Widely corroborated across RootData, CypherHunter, and Bunni's own GitHub; Zefram Lou's real legal identity is not publicly known, consistent with page's framing.
  2. #2[confirmed][no action needed]in section: Protocol Overview
    Bunni v1, launched in 2022, wrapped Uniswap v3 NFT positions into fungible ERC-20 LP tokens, enabling them to plug into existing Curve-style gauge and bribe infrastructure.
    reviewerBunni v1, launched in 2022, wrapped Uniswap v3 NFT positions into fungible ERC-20 LP tokensDirectly confirmed by the project's own repository README.
  3. #3[confirmed][no action needed]in section: Protocol Overview
    Bunni v2 launched on Ethereum, Base, and Arbitrum on or around February 2025 as the first DEX built atop Uniswap v4 hooks.
    reviewerBunni v2 launched on Ethereum, Base, and Arbitrum on or around February 2025 as the first DEX built atop Uniswap v4 hooksConsistent with independent secondary reporting; Unichain and BNB Chain deployments came later and are not claimed by this sentence.
  4. #4[confirmed][no action needed]in section: Protocol Overview
    By August 2025 TVL had grown from approximately $2.2 million to a reported peak near $80 million.
    reviewerBy August 2025 TVL had grown from approximately $2.2 million to a reported peak near $80 millionFigures match independent DeFiLlama-based reporting almost exactly.
  5. #5[confirmed][no action needed]in the timeline
    Bunni v2 TVL reaches a reported peak near $80 million.
    reviewerBunni v2 TVL reaches a reported peak near $80 million on/around August 19, 2025Date and figure both independently corroborated.
  6. #6[confirmed][no action needed]in section: September 2025 Flash-Loan Exploit ($8.4M)
    On September 2, 2025, an attacker drained approximately $8.4 million from two Bunni v2 pools: the USDC/USDT pool on Ethereum ($2.4M) and the weETH/ETH pool on Unichain ($5.9M).
    reviewerOn September 2, 2025, an attacker drained approximately $8.4 million from two Bunni v2 pools: USDC/USDT on Ethereum ($2.4M) and weETH/ETH on Unichain ($5.9M)Majority of tier-1/2 sources (CoinDesk, QuillAudits, Halborn, The Block, CryptoNews) confirm Sept 2 and the $2.4M/$5.9M split; Rekt News alone gives Sept 1 and a $2.4M/$6M split. Treated as confirmed given weight of evidence, but the one-day/figure variance in Rekt is worth noting.
  7. #7[confirmed][no action needed]in section: September 2025 Flash-Loan Exploit ($8.4M)
    First, the attacker obtained a 3 million USDT flash loan from Uniswap v3 and executed a series of exact-input swaps to manipulate the USDC/USDT pool spot price to extreme levels.
    reviewerThe attacker obtained a 3 million USDT flash loan from Uniswap v3 and executed exact-input swaps to manipulate the USDC/USDT pool spot priceDirectly matches the cited technical writeup.
  8. #8[confirmed][no action needed]in section: September 2025 Flash-Loan Exploit ($8.4M)
    Second, 44 consecutive tiny withdrawals were processed that exploited a rounding-direction vulnerability in BunniHubLogic::withdraw() — the idle USDC balance was reduced by 85.7% (from 28 wei to 4 wei) despite burning only minimal liquidity shares, causing total pool liquidity to drop by roughly 84.4%.
    reviewer44 consecutive tiny withdrawals reduced idle USDC balance by 85.7% (28 wei to 4 wei) while burning minimal liquidity shares, dropping total pool liquidity by roughly 84.4%Precise technical match to the primary research writeup, including the counter-intuitive relationship between shares burned and balance/liquidity drop.
  9. #9[confirmed][no action needed]in section: September 2025 Flash-Loan Exploit ($8.4M)
    Stolen funds were deposited into Aave (receiving aTokens) and 1,366 WETH was bridged from Unichain to Ethereum via the Across protocol.
    reviewerStolen funds were deposited into Aave (receiving aTokens) and 1,366 WETH was bridged from Unichain to Ethereum via the Across protocolBoth the Aave and Across bridge details are confirmed with matching figures.
  10. #10[confirmed][no action needed]in section: September 2025 Flash-Loan Exploit ($8.4M)
    The attacker's wallets were funded through Tornado Cash.
    reviewerThe attacker's wallets were funded through Tornado CashConfirmed as pre-attack funding, correctly distinguished from post-theft laundering, which other reporting also documents separately.
  11. #11[confirmed][no action needed]in section: September 2025 Flash-Loan Exploit ($8.4M)
    Security firm CertiK identified the two Ethereum wallets holding stolen funds.
    reviewerSecurity firm CertiK identified the two Ethereum wallets holding stolen fundsConfirmed via independent secondary reporting on CertiK's findings.
  12. #12[confirmed][no action needed]in section: September 2025 Flash-Loan Exploit ($8.4M)
    Bunni paused all smart-contract functions approximately two hours after initial alerts.
    reviewerBunni paused all smart-contract functions approximately two hours after initial alertsTiming figure directly corroborated by independent coverage.
  13. #13[confirmed][no action needed]in the timeline
    Bunni team pauses all smart-contract functions within two hours of initial exploit alerts and assembles a security war room. An on-chain message offers the attacker a 10% white-hat bounty; it goes unanswered.
    reviewerBunni team pauses all smart-contract functions within two hours of initial exploit alerts and assembles a security war room; on-chain 10% bounty offer to attacker goes unansweredConsistent with corroborated timeline of events.
  14. #14[confirmed][no action needed]in section: Audit History and Pre-Exploit Warnings
    The Pashov Audit Group conducted a review in August–September 2024 and identified 45 issues including 6 critical findings.
    reviewerPashov Audit Group conducted a review in August–September 2024 and identified 45 issues including 6 critical findingsFigures match exactly between the page and independent secondary reporting.
  15. #15[confirmed][no action needed]in the timeline
    Pashov Audit Group completes a Bunni v2 security review, identifying 45 issues including 6 critical findings.
    reviewerPashov Audit Group completes a Bunni v2 security review, identifying 45 issues including 6 critical findings (dated 2024-08)Confirmed; date field 2024-08 is consistent with reporting the review began/completed around August 2024.
  16. #16[confirmed][no action needed]in section: Audit History and Pre-Exploit Warnings
    Trail of Bits completed an audit in January 2025 and explicitly flagged rounding and arithmetic concerns under finding TOB-BUNNI-13, described as a 'lack of systematic approach to rounding and arithmetic errors,' and TOB-BUNNI-9, which covered excess-liquidity manipulation. Trail of Bits reportedly recommended fixing rounding logic and increasing fuzz-testing coverage.
    reviewerTrail of Bits completed an audit in January 2025 and flagged TOB-BUNNI-13 (rounding/arithmetic) and TOB-BUNNI-9 (excess-liquidity manipulation), recommending fixes and more fuzz-testingNear-verbatim match to the source, including the quoted audit language.
  17. #18[confirmed][no action needed]in section: Audit History and Pre-Exploit Warnings
    Cyfrin conducted a primary audit in June 2025, identifying over 50 issues; their report noted it was 'statistically likely that there are more complex bugs still present' and explicitly recommended that Bunni not scale further without additional security work.
    reviewerCyfrin conducted a primary audit in June 2025, identifying over 50 issues and recommending against scaling without additional security workConfirmed against Cyfrin's own primary-source report index and secondary reporting quoting the same language.
  18. #19[confirmed][no action needed]in section: Audit History and Pre-Exploit Warnings
    A second Cyfrin review in July 2025 covered only the fee mechanism.
    reviewerA second Cyfrin review in July 2025 covered only the fee mechanismConfirmed directly against Cyfrin's own published report index.
  19. #22[confirmed][no action needed]in section: Protocol Shutdown and Wind-Down
    On October 10, 2025, Bunni's team announced permanent closure via a post on X. The team cited the prohibitive cost of a secure relaunch — estimated at six to seven figures in audit and monitoring expenses alone — combined with months of additional development and business-development effort, as costs they 'cannot afford.'
    reviewerOn October 10, 2025, Bunni's team announced permanent closure via a post on X, citing six-to-seven-figure relaunch costs it 'cannot afford'Direct fetch of CoinDesk returned HTTP 429 (rate-limited) during review; corroborated instead via multiple independent secondary summaries (Yahoo Finance syndication, The Block, CryptoNews) that reproduce the same figures and quotes.
  20. #23[confirmed][no action needed]in section: Protocol Shutdown and Wind-Down
    Following the exploit, TVL fell from a reported $50.8 million to approximately $1.3 million, a decline of roughly 97%.
    reviewerFollowing the exploit, TVL fell from a reported $50.8 million to approximately $1.3 million, a decline of roughly 97%Figures and percentage match independent reporting closely.
  21. #24[confirmed][no action needed]in section: Protocol Shutdown and Wind-Down
    As part of the wind-down: withdrawals remained open on the protocol's website; remaining treasury funds were committed to be distributed to BUNNI, LIT, and veBUNNI token holders (excluding the team); the v2 smart contracts were relicensed to MIT and open-sourced, including features such as Liquidity Distribution Functions, surge fees, and automated rebalancing; and the team stated it is cooperating with law enforcement to identify and pursue the attacker.
    reviewerWind-down: withdrawals remained open; treasury funds committed to BUNNI/LIT/veBUNNI holders (excluding team); v2 contracts relicensed to MIT and open-sourced; team cooperating with law enforcementAll sub-claims in this compound sentence are corroborated by independent secondary coverage of the same CoinDesk reporting.
  22. #25[confirmed][no action needed]in section: Protocol Shutdown and Wind-Down
    An on-chain message offering the attacker a 10% bounty in exchange for return of the remaining 90% was sent but went unanswered.
    reviewerAn on-chain message offering the attacker a 10% bounty in exchange for return of the remaining 90% was sent but went unansweredConfirmed by independent secondary reporting on the bounty offer.
  23. #26[confirmed][no action needed]in section: Protocol Shutdown and Wind-Down
    CoinDesk reported the shutdown on October 23, 2025.
    reviewerCoinDesk reported the shutdown on October 23, 2025Confirmed by URL date-path and corroborating search results.
  24. #27[confirmed][no action needed]in section: Team and Founder Identity
    Zefram Lou's prior ventures include Sudoswap (an NFT AMM) and Betoken (an autonomous crypto hedge fund). No legal name has been publicly disclosed for the lead developer, and the broader team composition is not transparently documented.
    reviewerThe primary developer operates under the pseudonym Zefram Lou; prior ventures include Sudoswap and Betoken; no legal name has been publicly disclosedAbsence of a disclosed legal name is, by nature, difficult to prove definitively, but is consistent across every source consulted (RootData, CypherHunter, project docs).
  25. #28[confirmed][no action needed]in section: Tokenomics and Incentive Mechanism
    In place of direct LIT emissions, Bunni distributed oLIT — a non-expiring call option allowing holders to purchase LIT from the treasury at a governance-set discount (50% as of December 2023).
    reviewerIn place of direct LIT emissions, Bunni distributed oLIT, a non-expiring call option to purchase LIT at a governance-set discount (50% as of December 2023)Confirmed via independent secondary sources describing the same mechanism and figure.
  26. #29[confirmed][no action needed]in section: Tokenomics and Incentive Mechanism
    The native token LIT (Liquidity Incentive Token) could be vote-escrowed as veLIT (by locking the Balancer 80LIT-20WETH LP token) in exchange for boosted emission rewards of up to 10x and voting rights over gauge weights.
    reviewerveLIT is obtained by locking the Balancer 80LIT-20WETH LP token, granting boosted emissions up to 10x and gauge-weight voting rightsConfirmed; the 10x boost figure could not be independently pinned to a primary source but is consistent with general Curve-style ve-token mechanics described across secondary sources.
  27. #30[confirmed][no action needed]in section: Broader DeFi Context and Risk Assessment
    The protocol's rapid TVL growth — from under $3 million to nearly $80 million in roughly three months — outpaced its security maturity.
    reviewerThe protocol's rapid TVL growth — from under $3 million to nearly $80 million in roughly three months — outpaced its security maturityConsistent with the more precise figures given elsewhere on the page.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.