CryptoReal
CASE FILE — Aug 14, 2023

Price-Manipulation Attack Depegs Zunami's zETH and UZD Stablecoins for $2.1M

Editor's note: This piece has been updated to remove a reference to Ackee Blockchain, which had audited an earlier version of Zunami's protocol — one that predated the addition of the MimCurveStakeDAO strategy later targeted in this attack.

Zunami Protocol lost $2.1 million the day before this report after its Ether- and dollar-pegged stablecoins were hit by a price-manipulation attack. Curve's core infrastructure was not itself compromised, but the attacker drained liquidity from Zunami's zETH and UZD pools on Curve, causing zETH to depeg by 85% and UZD to depeg by 99%.

Security firm Peckshield was first to flag unusual activity, but — mindful of recent criticism directed at BlockSec over its live-tweeting of the Curve exploit — initially withheld transaction hashes and addresses from its alert. Zunami itself soon acknowledged the incident, stating: "It appears that zStables have encountered an attack. The collateral remain secure, we delve into the ongoing investigation."

This adds Zunami to a growing list of Curve-ecosystem casualties in recent months, following Conic Finance and, more recently, JPEG'd, Alchemix, and Curve's own Vyper-related exploit — a pattern that raises the question of whether the Curve Wars have become more profitable for attackers than for the protocols competing in them.

01Mechanism of the exploit

About an hour after its initial alert — once it appeared no further funds were at risk — Peckshield published additional detail, describing the root cause as "a price manipulation issue, which can be exploited by donation to incorrectly calculate the price."

In practice, the attacker used flash loans to execute large swaps of tokens including SDT, deliberately inducing slippage in the pool. That slippage was then used to distort the calculated price of LP tokens, exploiting a flaw in how the protocol's totalHoldings function computed value. BlockSec separately published its own step-by-step account of the exploit sequence.

The stolen proceeds — 1,184 ETH, roughly $2.1 million — were quickly funneled into Tornado Cash.

Zunami's core protocol, along with its UZD and zETH contracts, had been audited by Hashex.

02Key addresses and transactions

The attacker's wallet has been identified as 0x5f4c21c9bb73c8b4a296cc256c0cde324db146df. The exploit was executed across two transactions: one targeting zETH (0x2aec4fdb2a09ad4269a410f2c770737626fb62c54e0fa8ac25e8582d4b690cca) and one targeting UZD (0x0788ba222970c7c68a738b0e08fb197e669e61f9b226ceec4cab9b85abe8cceb).

Notably, the Sushiswap SDT pool used by the attacker during the manipulation was itself not compromised or at fault, despite some social-media speculation suggesting otherwise.

03Disclosure norms under scrutiny

Not every security researcher exercised the same restraint as Peckshield in withholding sensitive detail; other accounts posted more freely, both here and here. This follows a broader debate that emerged after BlockSec's public breakdown of the Vyper compiler bug the prior month, which drew criticism over whether security firms were prioritizing visibility on social media at the potential expense of aiding active exploiters. That controversy, along with subsequent calls for better norms, appears to have pushed firms like BlockSec toward revised alerting practices that share only what's necessary for affected users to protect funds, without handing attackers a roadmap.

A related effort, the SEAL 911 hotline, operates as a Telegram-based rapid-response system, drawing on a curated list of vetted responders to help notify protocol teams of active threats.

Security researchers continue to play an essential role in DeFi, including BlockSec's own track record of white-hat interventions across multiple incidents. Even so, the Zunami case is a reminder that defensive efforts remain reactive by nature, and not every exploit can be caught before funds move.

Zunami Protocol
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.