CryptoReal
CASE FILE — Jul 18, 2021

PancakeBunny Gets Hit Again — $2.4M Drained From Its Polygon Vaults

Two months after PancakeBunny's original $45 million exploit on BNB Smart Chain, the protocol suffered a similar attack on Polygon, this time losing $2.4 million — enough to earn it a second, separate entry (#33) on the rekt leaderboard. REKT itself flagged the irony in a tweet titled "We sent it back, and then they lost it."

PancakeBunny has said it plans to compensate affected users, suggesting the team intends to keep operating despite the repeat failure. Accusations that the exploit was an inside job have circulated, but according to DeFiLlama, the protocol's total value locked has been gradually recovering regardless.

How the exploit worked

Per PancakeBunny's own post-mortem, the attacker — operating from address 0xa6021d8c36b2de6ceb4fe281b89d37d2be321431 — made a very small deposit into one of PancakeBunny's vaults while simultaneously depositing a much larger amount directly into SushiSwap's MiniChefV2 contract. Calling the withdrawAll function then let the attacker treat that large MiniChefV2 deposit as accrued interest, exploiting the polyBUNNY minting logic. The full attack transaction is recorded on PolygonScan.

Step by step, the attacker:

Sums referenced in this case file
  1. Deposited 0.000000009416941138 SLP (about $19,203) into PancakeBunny's Polygon USDT-USDC vault.
  2. Deposited 0.000023532935903931 SLP (about $47,990,975) into the USDT-USDC MiniChefV2 contract on SushiSwap.
  3. Triggered a performance fee of 0.000007006743943544 SLP (about $14,284,950), which minted 2.1 million polyBUNNY tokens to the attacker.
  4. Sold the minted polyBUNNY for WETH.
  5. Repaid an Aave flash loan used to fund the attack and exited with a net gain of 1,281.702952074137533313 ETH.

The resulting sell-off pushed polyBUNNY's price down from about $10 to $1.78.

Not the first time this exact bug appeared

The same underlying exploit had already been used two days earlier against ApeRocketFi, a direct fork of PancakeBunny's code, as PeckShield noted on Twitter. That attack cost ApeRocket $260,000 on BNB Smart Chain and $1 million on Polygon — yet PancakeBunny apparently did nothing to close the same hole in its own code before it was hit in turn.

The timing raises an obvious question: was the ApeRocket attack a dry run meant to confirm the technique before turning to the larger protocol? And if so, why risk alerting PancakeBunny to the vulnerability at all, unless the attacker had reason to believe it wouldn't matter? It remains possible the two attacks were carried out by different people who independently found the same flaw, or who simply didn't realize the vulnerability carried over from the forked code — though the timing makes that explanation feel like a stretch.

PancakeBunnyPolygon
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.