Bunker Finance exploited via oracle manipulation in NFT lending market; attacker flash-loaned a CryptoPunk, over-collateralized it using a manipulated price feed, drained ~$5.6K across two markets.
Security & Exploits ·
Bunker Finance, a CryptoPunk-collateralized lending protocol, suffered an exploitation on July 16 that drained approximately $5.6K in value. The attacker executed a flash-loan attack by borrowing a CryptoPunk from NFTX, redeeming it, and depositing it into Bunker's NFT lending markets as collateral. The protocol's price oracle valued the NFT using the NFTX vault's Uniswap floor price, resulting in a significant overvaluation of the individual asset.
Using the inflated collateral value, the attacker borrowed across two separate comptrollers: 1.59 ETH and 1,297 USDC from one market, then 1.1 ETH and 50 USDC from another. The attacker then withdrew the same CryptoPunk and returned it to NFTX to repay the initial flash loan, leaving the borrowed funds unbacked. The net extraction totaled approximately 2.69 ETH and 1,297 USDC.
The core vulnerability stemmed from the protocol's reliance on a single, manipulable price feed for NFT collateral valuation combined with the ability to redeem collateral without triggering liquidity checks. The exact mechanisms that allowed the withdrawal to bypass solvency constraints remain a specific point of technical concern, though the flash-loan structure provided the necessary capital to execute the exploit in a single transaction.