Second BSC Exploit Drains $57 Million From Uranium Finance's Forked Uniswap Contracts
Uranium Finance, a Uniswap clone running on BNB Smart Chain, lost at least $57 million on April 28, 2021, after an attacker exploited a math error introduced into its UraniumPair contracts — a codebase forked from Uniswap v2. It was not the protocol's first security incident: earlier in the same month, Uranium had already suffered an exploit of its rewards system after vulnerabilities were introduced into its MasterChef contract. By the time this second incident was reported, roughly 2,200 ETH of the stolen funds — out of the roughly $57.2 million total — had already been routed through Tornado.cash.
The Bug

bZx co-founder Kyle Kistner identified the specific change responsible: in the UraniumPair contract, a constant of 1,000 had been altered to 10,000 in two places, but not in a third, related spot. That inconsistency let an attacker swap a single wei of an input token for roughly 98% of a pair's total output-token balance. As researcher 0xdeadf4ce explained, the mismatch broke the check meant to enforce Uniswap v2's x*y=k constant-product formula before fee-adjusted reserve balances were updated.
The attacker's method was simple once the flaw was in place: send the minimum possible amount of each token into the pair contracts, then call the low-level swap() function in a way that drained both reserves at once.
What Was Taken
The funds removed from the pools included:
- 34,000 WBNB (~$18M)
- 17.9 million BUSD (~$17.9M)
- 1,800 ETH (~$4.7M)
- 80 BTC (~$4.3M)
- 26,500 DOT (~$0.8M)
- 638,000 ADA (~$0.8M)
- 5.7 million USDT (~$5.7M)
- 112,000 U92
Timeline and Suspicious Circumstances
Uranium's team had migrated the protocol to its "v2" contracts about ten days before the exploit; the prior version did not contain this bug. The team had also already scheduled a further upgrade, v2.1, whose only material change was a fix for this exact flaw — with the liquidity migration to v2.1 due to begin on the same day the exploit occurred. In other words, the vulnerable code had been live for roughly ten days and was drained on the very day it was set to be patched.
Adding to the suspicion, Uranium's contract repository was subsequently removed from GitHub (credit for this observation goes to Igor Igamberdiev). The circumstances left open two competing explanations: either the bug was inserted deliberately and the v2.1 migration was meant to quietly erase it, or an outside party discovered the flaw independently and moved to exploit it just before the team could ship its fix.

Broader Pattern
The incident reflected a wider trend of cross-chain exploits. BSC is no longer a closed system — multiple bridges now lead off the chain, not all of them under Binance's control, which means CZ cannot unilaterally blacklist addresses to keep stolen funds contained on BSC. Attackers increasingly steal on one chain and exit through another where tracing is harder; at the time, Tornado.cash was the only application enabling that kind of exit, though similar tools on other chains were expected to follow.
With roughly $57.2 million in liquid assets, the party behind this exploit ended up with a considerably more valuable haul than the illiquid EASY tokens taken in the EasyFi incident covered previously, placing this exploit in second place on rekt's leaderboard at the time. Exploits and rug pulls of this kind were expected to continue, if not accelerate — even with battle-tested codebases like Curve and Uniswap available as references, users kept gravitating toward newer, unaudited forks in search of higher returns. A further shift was anticipated too: a future in which attackers operate on fully private chains and no longer need to move funds off-chain to stay hidden at all.
Get new scam files the moment we publish them — usually 2–3 emails a week.