Two successful Ethereum transactions at 22:26:35 and 22:34:47 UTC on August 13, 2023 exploited Zunami Protocol’s valuation logic, allowing the same address to extract an estimated 1,178 ETH after repaying flash loans. CertiK valued the combined loss at approximately $2.16 million. The Ethereum record fixes the attack to August 13 even though Zunami’s public warning arrived after midnight UTC on August 14.

Zunami was a decentralized yield aggregator whose UZD and zETH instruments represented claims on pooled strategies. Those tokens traded through Curve pools, so an error inside Zunami’s accounting could travel outward: a temporarily overstated protocol balance could become spendable liquidity in an external market.

A cached price became the attack surface

The larger transaction combined temporary liquidity from Uniswap and Balancer: 7 million USDT, 7 million USDC and 10,011 wrapped ether, according to CertiK’s reconstruction. A flash loan must be borrowed and repaid within one transaction; its purpose here was not long-term financing, but enough momentary scale to move thin markets and exploit a calculation before the transaction ended.

The attacker first acquired UZD, then sent Stake DAO’s SDT token to Zunami’s MIMCurveStakeDAO strategy. Large swaps on SushiSwap altered the spot relationships used to value SDT. The attacker then called Zunami’s public cacheAssetPrice function while those inputs were distorted.

CertiK calculated that this sequence made the attacker’s displayed UZD balance rise from 4,873,316 UZD to about 16,902,957 UZD. That was an accounting result, not the creation of equivalent external dollar reserves. The attacker exchanged the overstated UZD through Curve, reversed the market-moving swaps, repaid the flash loans and retained approximately 1,152 WETH from the larger transaction. A smaller transaction eight minutes earlier brought the security firm’s combined estimate to roughly 1,178 ETH.

This was price manipulation in a specific technical sense. The vulnerable calculation depended on token balances held by the strategy and prices derived from immediately tradable decentralized-exchange pools. Both could be changed inside one atomic transaction. Caching the manipulated result let another contract read the inflated value before markets and balances were restored.

What the loss estimate measured

The $2.16 million figure was CertiK’s contemporaneous-equivalent valuation of approximately 1,178 ETH, not verified U.S. dollars received by the attacker. Etherscan records an Ether reference price of $1,839.10 for the first transaction; multiplying that reference by 1,178 gives about $2.17 million, consistent with the rounded estimate. That calculation does not include every fee, slippage effect or later transfer, and it should not be read as realized cash proceeds.

Zunami’s August 14 public statement advised users not to buy UZD or zETH because their “emission” had been attacked. The team also said collateral remained secure while it investigated. That collateral statement was a contemporaneous protocol claim, not an independently completed accounting on August 13.

The incident mattered beyond its dollar size because UZD was presented as a stable instrument. A stablecoin design can fail without its reserve assets being directly stolen if the system issues or recognizes more redeemable claims than its economic backing supports. The exploit also demonstrated the composability risk of decentralized finance: flash liquidity, spot prices, internal accounting and external Curve liquidity interacted as one attack path.

Later technical context

On August 31, 2023, Ackee Blockchain said the attacked MIMCurveStakeDAO strategy had been added after the earlier Zunami version it audited. Ackee’s later analysis identified the combination of manipulable strategy valuation and block-level price caching as the root cause. That finding clarifies the August 13 record; it was not yet available when the transactions executed.

Primary sourceEtherscan — first Zunami exploit transaction at 22:26:35 UTC

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.