logo

Zunami Protocol Incident Analysis

ID: 4f5c5c0d-7097-5fed-b7ea-69ca7505aa37

STIX ID: report--4f5c5c0d-7097-5fed-b7ea-69ca7505aa37

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2023-08-16

Date Updated: 2026-06-11

...
...

On 13 August 2023 the Zunami Protocol was exploited via a complex flash-loan attack that manipulated SDT prices on SushiSwap and the cached UZD asset price, inflating the attacker’s UZD balance from ~4.8M to ~16.9M and resulting in a theft of ~1,178 ETH (~$2.16M). The attacker executed large flash loans across Uniswap V3 and Balancer, performed multi-step swaps through Curve and SushiSwap, called cacheAssetPrice() to corrupt the UZD valuation, repaid the loans, and laundered proceeds through Tornado Cash; the report includes transaction references, vulnerable functions (cacheAssetPrice/assetPriceCached/totalHoldings), affected pools, and broader flash-loan statistics for August 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.