<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Zunami_Protocol_Pool_Price_Imbalance_Arbitrage_Exploit</id>
	<title>Zunami Protocol Pool Price Imbalance Arbitrage Exploit - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Zunami_Protocol_Pool_Price_Imbalance_Arbitrage_Exploit"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Zunami_Protocol_Pool_Price_Imbalance_Arbitrage_Exploit&amp;action=history"/>
	<updated>2026-04-21T11:19:57Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Zunami_Protocol_Pool_Price_Imbalance_Arbitrage_Exploit&amp;diff=6777&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/zunamiprotocolpoolpriceimbalancearbitrageexploit.php}} {{Unattributed Sources}}  Zunami Protocol Logo/Homepage&lt;ref name=&quot;zunamirekt2-20210&quot; /&gt;&lt;ref name=&quot;zunamiprotocolmedium-20211&quot; /&gt;&lt;ref name=&quot;etherscan1-20216&quot; /&gt;&lt;ref name=&quot;etherscan2-20217&quot; /&gt;&lt;ref name=&quot;etherscan3-20218&quot; /&gt;&lt;ref name=&quot;etherscan4-20219&quot; /&gt;&lt;ref name=&quot;etherscan5-20220&quot; /&gt;&lt;ref name=&quot;ethersc...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Zunami_Protocol_Pool_Price_Imbalance_Arbitrage_Exploit&amp;diff=6777&amp;oldid=prev"/>
		<updated>2025-06-16T22:41:02Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/zunamiprotocolpoolpriceimbalancearbitrageexploit.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Zunamiprotocol.jpg&quot; title=&quot;File:Zunamiprotocol.jpg&quot;&gt;thumb|Zunami Protocol Logo/Homepage&lt;/a&gt;&amp;lt;ref name=&amp;quot;zunamirekt2-20210&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zunamiprotocolmedium-20211&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan1-20216&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan2-20217&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan3-20218&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan4-20219&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan5-20220&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ethersc...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/zunamiprotocolpoolpriceimbalancearbitrageexploit.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Zunamiprotocol.jpg|thumb|Zunami Protocol Logo/Homepage]]&amp;lt;ref name=&amp;quot;zunamirekt2-20210&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zunamiprotocolmedium-20211&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan1-20216&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan2-20217&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan3-20218&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan4-20219&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan5-20220&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan6-20221&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan7-20222&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan8-20223&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan9-20224&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan10-20225&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan11-20226&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan12-20227&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan13-20228&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;compensationplan-20214&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;compensationspreadsheet-20229&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;rekthqtweet-20215&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zunamihomepage-20193&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Zunami Protocol ==&lt;br /&gt;
Zunami Protocol is a decentralized finance (DeFi) platform designed to optimize yield generation through aggregated stablecoins and omnipools. At its core, Zunami issues aggregated stablecoins like zunUSD and zunETH, which are backed by diversified assets in yield-generating strategies across various DeFi protocols. These assets are held in omnipools, which combine liquidity and flexibility, enabling efficient, decentralized, and profitable collateral management.&lt;br /&gt;
&lt;br /&gt;
The omnipools are structured to maximize returns—offering users an average APY of around 20%—by distributing capital across multiple DeFi platforms such as Curve Finance, Convex Finance, Stake DAO, FRAX Finance, and C.R.E.A.M. Finance. The collateral within these pools is managed through DAO voting, ensuring that strategy adjustments are community-driven. Zunami’s Algorithmic Peg Stabilizer (APS) further ensures that stablecoin prices remain steady, automatically rebalancing portfolios and compounding yields.&lt;br /&gt;
&lt;br /&gt;
The ZUN token powers governance and liquidity functions within the ecosystem. Holders can vote on protocol decisions, manage liquidity-as-a-service (LaaS), influence token emissions, and earn rewards through staking. Notably, ZUN stakers act as an additional collateral layer, reinforcing stability and receiving 100% of the protocol’s revenue in return.&lt;br /&gt;
&lt;br /&gt;
Security-wise, Zunami has emphasized decentralization with no proxy contracts, DAO-based risk management, and independent audits. Its open documentation and Gitbook provide full technical transparency. In sum, Zunami Protocol is an innovative approach to stablecoin yield farming—combining aggregation, decentralization, and automated strategy execution.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
After suffering a sandwich attack, the Zunami Protocol was left in a position of arbitrage, which was able to be exploited for additional profit.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
An attacker was able to exploit low liquidity in the DAI/USDC pair, creating a price discrepancy exploitable through a flashloan attack to drain liquidity pools.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Zunami Protocol Pool Price Imbalance Arbitrage Exploit&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|January 26th, 2023 7:14:23 AM MST&lt;br /&gt;
|Stablecoin Swap Sandwich Attack&lt;br /&gt;
|The Zunami Protocol team swaps 66,888 DAI and receives only 17,230 USDC due to a sandwich attack against their transaction in the mempool. This is reportedly &amp;quot;while transferring funds to the new XAI + FRAXBP pool&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|January 29th, 2023 4:14:00 PM MST&lt;br /&gt;
|Silo Finance Sees Deposit Already&lt;br /&gt;
|Silo Finance reports on the sandwich attack transaction as &amp;quot;a 130k XAI-FRAXBP deposit&amp;quot; in a tweet shortly after an announcement of a partnership between the two projects.&lt;br /&gt;
|-&lt;br /&gt;
|February 3rd, 2023 9:00:11 AM MST&lt;br /&gt;
|First Arbitrage Transactions&lt;br /&gt;
|The first arbitrage swap which is exploiting the price discrepancy.&lt;br /&gt;
|-&lt;br /&gt;
|February 3rd, 2023 9:00:47 AM MST&lt;br /&gt;
|Final Arbitrage Transactions&lt;br /&gt;
|The final arbitrage transaction which exploits the price discrepancy for profit.&lt;br /&gt;
|-&lt;br /&gt;
|February 5th, 2023 7:31:21 AM MST&lt;br /&gt;
|Zunami Protocol Attacked Twice&lt;br /&gt;
|An article is published on Medium which highlights two attacks against the Zunami Protocol.&lt;br /&gt;
|-&lt;br /&gt;
|February 8th, 2023 4:06:55 AM MST&lt;br /&gt;
|Zunami Protocol Compensation Plan&lt;br /&gt;
|Zunami publishes a compensation plan on their Medium. While the stolen funds cannot be recovered, the team ensures that current user funds are safe and has introduced changes to prevent future exploits. As part of the compensation, users who maintain their ZLP and UZD holdings through the end of 2023 without reducing balances will be eligible for reimbursement. The plan will be funded through the protocol’s treasury, a future insurance fund, bond market revenues, and development reserves.&lt;br /&gt;
|-&lt;br /&gt;
|June 13th, 2025 10:04:00 AM MDT&lt;br /&gt;
|Second Rekt Article Published&lt;br /&gt;
|Rekt News publishes a second article about Zunami Protocol which includes this exploit, after $500k goes missing from the protocol. The chief technology officer Mikhail Zelenin is a primary suspect, however he has a story about border security guards potentially holding his laptop for hours of analysis.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
The attack targeted a swap operation involving the conversion of 66,888 DAI to USDC via a decentralized exchange. This transaction was captured in the mempool before confirmation and manipulated through a classic sandwich attack — a strategy where an MEV bot places a transaction just before and after a victim’s swap to extract profit by manipulating token prices. Specifically, the attacker executed a front-running swap to skew the price curve against the victim, then allowed the victim’s transaction to execute at a worse rate, and finally executed a back-running swap to restore prices and pocket the arbitrage.&lt;br /&gt;
&lt;br /&gt;
As a result, Zunami received only 17,230 USDC for 66,888 DAI — far below the expected rate (implying a massive slippage and effective loss of ~$49,658). This shows the attacker was able to exploit liquidity asymmetries or low depth in the DAI/USDC pair, likely via SushiSwap or a related AMM pool, by inflating USDC price through their front-running trade and offloading after Zunami's unfavorable execution.&lt;br /&gt;
&lt;br /&gt;
The consequence extended beyond the direct loss. The artificially poor execution caused a distorted valuation of the Zunami LP token (ZLP) in the XAI + FRAXBP pool, dropping its price to $0.8213 while it remained at $1.1252 in the MIM pool. This mispricing opened the door for a second, more complex flashloan attack, where an attacker could buy ZLP cheaply in one pool and redeem it at the higher price in another — exploiting the price delta and lack of cross-pool price sync.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
According to the Zunami Protocol team, &amp;quot;In total, the attackers stole $260k.&amp;quot; This figure was also later included in an article published by Rekt News.&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $260,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
The Zunami team responded swiftly to the attack by halting all deposits and withdrawals within one hour to prevent further exploitation and ensure the safety of user funds. This immediate action helped contain the damage and allowed the team to assess the situation before resuming normal operations.&lt;br /&gt;
&lt;br /&gt;
To mitigate future risks, the team implemented several key security measures. They deployed a new contract for the XAI strategy with built-in amount controls to defend against MEV-style attacks. Additionally, direct deposits and withdrawals were capped at 100,000, making large-scale attacks economically unfeasible, while delegated transactions (handled by trusted intermediaries) remain unrestricted.&lt;br /&gt;
&lt;br /&gt;
Finally, the team is actively working on a compensation plan to reimburse users for the $260,000 lost across the two attacks. The plan is expected to be released in the coming days, reaffirming the team’s commitment to transparency and user protection.&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
Zunami published a plan to compensate users fully for their losses in this exploit.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The team reported to be preparing a compensation plan for the attack in a Medium article which they published entitled &amp;quot;The Zunami Protocol has come under two attacks&amp;quot; on February 5th, 2023.&lt;br /&gt;
&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
Zunami Protocol continues to operate, and would suffer future exploits.&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;zunamirekt2-20210&amp;quot;&amp;gt;[https://rekt.news/zunami-protocol-rekt2 Rekt - Zunami Protocol - Rekt II] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zunamiprotocolmedium-20211&amp;quot;&amp;gt;[https://zunamiprotocol.medium.com/the-zunami-protocol-has-come-under-two-attacks-e201a8a0ec6c The Zunami Protocol has come under two attacks - Zunami Protocol Medium] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan1-20216&amp;quot;&amp;gt;[https://etherscan.io/tx/0x9fe927823f58ddaeb18f40c665108941192881fe3daff86db6328c9cb723bc91 First Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan2-20217&amp;quot;&amp;gt;[https://etherscan.io/tx/0xc6ad352f7c6a5494669479d66f10730423f56e8a78d8dc11860c7bec7703f3c0 Second Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan3-20218&amp;quot;&amp;gt;[https://etherscan.io/tx/0xff7188719dc4f757b5d55e96644c733b48f79b74d7a3302e3313607577dd1e3c Third Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan4-20219&amp;quot;&amp;gt;[https://etherscan.io/tx/0x54b9779c50dc05ec7b5b184bfecd47962c89332ead00d31d830b995b3a75089b Fourth Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan5-20220&amp;quot;&amp;gt;[https://etherscan.io/tx/0x08167233162667f4b6803ac12607f57de48bcd502095ad90434f1a16e9f4b894 Fifth Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan6-20221&amp;quot;&amp;gt;[https://etherscan.io/tx/0xcc514c5dd367c6fd298148cb0c56dab499d4fd7dcc94b28ed2f0952cc15ec343 Sixth Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan7-20222&amp;quot;&amp;gt;[https://etherscan.io/tx/0x600b06f4cfaac69525998afb71a63f167d598c923e0b2f9932c86a863cc50611 Seventh Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan8-20223&amp;quot;&amp;gt;[https://etherscan.io/tx/0x0053946288abc81fc15eebf7517de7e05846e054f7aa8e69b9834cdbd2773518 Eighth Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan9-20224&amp;quot;&amp;gt;[https://etherscan.io/tx/0xbd3311c0dbd6049ff99a7bcd9f570c66a4ed176ed272e589cd85702dd2f493b0 Ninth Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan10-20225&amp;quot;&amp;gt;[https://etherscan.io/tx/0xe6eff1573606e80396b21f011510ac5c5415c45775b9af67a744b164f186f446 Tenth Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan11-20226&amp;quot;&amp;gt;[https://etherscan.io/tx/0x8e4ba72e5a7a152b22c778652d3b4062333e16acc1a30edcad1689bd193fbe96 Eleventh Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan12-20227&amp;quot;&amp;gt;[https://etherscan.io/tx/0xf28c50293342dcaba5be567ace113ec1ed40f940bea8a97a1cf253361c2bf062 Twelfth Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan13-20228&amp;quot;&amp;gt;[https://etherscan.io/tx/0x59b92c023d0e7c0749b92a1252fb7fdc23061da2a8d853a406587f8173a33183 Thirteenth Arbitrage Swap Transaction - Etherscan] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;compensationplan-20214&amp;quot;&amp;gt;[https://zunamiprotocol.medium.com/compensation-plan-2964af44976 Compensation Plan - Zunami Protocol Medium] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;compensationspreadsheet-20229&amp;quot;&amp;gt;[https://docs.google.com/spreadsheets/d/1iR5WJi-8xeAY6cEg3oVFKbsx1j23WALYsZwLX-MRtI0/edit Spreadsheet For Compensation - Google Sheet] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;rekthqtweet-20215&amp;quot;&amp;gt;[https://twitter.com/RektHQ/status/1933556211108229310 Rekt HQ - &amp;quot;$500k vanished from @ZunamiProtocol in a May admin key exploit. Months of stagnant development &amp;amp; perfect timing may have paved the way. Team offered weak excuses, dismissed concerns, left users empty-handed. When emergency keys open doors, who's in control? Story in comments.&amp;quot; - Twitter/X] (Accessed Jun 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zunamihomepage-20193&amp;quot;&amp;gt;[https://www.zunami.io/ Zunami Protocol Homepage] (Accessed Jun 11, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>