CryptoReal
CASE FILE — May 20, 2021

8 Flash Loans, One Price Oracle Flaw: How PancakeBunny Lost $45M

PancakeBunny Finance lost approximately $45 million in an attack that exploited a flaw in how the protocol priced its PancakeSwap liquidity-provider tokens, specifically the BNB-BUSDT and BNB-BUNNY pairs. The attacker later mocked the protocol on Twitter, calling flash loans "earitating."

Using a chain of eight flash loans, the attacker manipulated prices across several PancakeSwap pools, distorting the valuation calculation used by the VaultFlipToFlip vault. That distortion allowed 697,000 BUNNY tokens to be minted and immediately sold, crashing BUNNY's price from $146 to $6. PeckShield published a root-cause analysis of the incident, and the exploit transaction is recorded on BscScan.

Attack sequence

The attacker opened with eight simultaneous flash loans — seven drawn from various PancakeSwap pools, and an eighth from Fortube Bank:

  • 1.05M WBNB from the WBNB+CAKE pool
  • 522.52K WBNB from the WBNB+BUSD pool
  • 210.16K WBNB from the WBNB+ETH pool
  • 133.50K WBNB from the WBNB+BTCB pool
  • 241.02K WBNB from the WBNB+SAFEMOON pool
  • 98.519K WBNB from the WBNB+BELT pool
  • 66.29K WBNB from the WBNB+DOT pool
  • 2.96M USDT from Fortube Bank
Sums referenced in this case file

With those funds, the attacker deposited 2.96M USDT and 7,886 WBNB as liquidity into the WBNB+BUSDT pool, minting 144.45K LP tokens. They then swapped 2.32M WBNB for 3.83M BUSDT through that same pool, deliberately inflating its WBNB reserve — a reserve size that fed directly into how the pool's LP tokens were valued.

With LP token valuation now artificially inflated, the attacker called the getReward() function on VaultFlipToFlip, harvesting a reward of 6.97M BUNNY (worth over $1 billion on paper at the time); the protocol's own dev team separately received 1.05M BUNNY through the same mechanism. All eight flash loans were then repaid to their respective PancakeSwap pools and Fortube Bank, leaving the attacker with the minted BUNNY. Proceeds were initially routed to the wallet 0xa0acc61547f6bd066f7c9663c17a312b6ad7e187.

Impact

Pancake Bunny reportedly held over $10 billion in total value locked at its peak; by the time of the original reporting, that figure had fallen to just over $1 billion. A prior audit from Haechi had not been enough to stop the flash-loan attack, and the size of the loss put PancakeBunny in joint third place on the rekt leaderboard. The same day also saw Venus Protocol and a project referenced on Twitter as "wArOnrUgS" suffer their own incidents within hours of PancakeBunny's exploit.

Update — July 18, 2021

Haechi later issued a statement clarifying its role in the matter: its original audit had specifically flagged that PancakeBunny relied on non-audited, changeable external contracts, and that a "helper" function was vulnerable to flash loan attacks. PancakeBunny subsequently upgraded its smart contracts and engaged a different auditing firm for the new code — meaning the flash loan exploit involved contracts Haechi had never audited. Further details were shared on Twitter.

BSCPancakeBunny
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.