BurgerSwap Hack
What happened
On May 28, 2021, BurgerSwap's BNB Smart Chain AMM was exploited in 14 transactions for about $7.2 million. Flash liquidity from PancakeSwap funded the operation, but the drain depended on reentrancy through a malicious token and faulty AMM reserve validation.
BurgerSwap's Uniswap V2-derived swap path allowed callback-driven reentrancy and lacked the constant-product invariant validation needed to reject a second output calculated from stale reserves.
Case & protocol details
Attack Timeline
The attacker created a non-standard token and paired it with BURGER. During a multi-hop swap, the token re-entered BurgerSwap before the relevant reserves were safely settled. Because the protocol lacked the constant-product invariant check used in Uniswap V2, it could honor a second output using stale accounting.
The flash swap was repaid within the transaction, leaving the extracted assets as the result.
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Report twitter.com
- report Post-mortem rekt.news
- report Decrypt: BurgerSwap Postmortem decrypt.co
- transaction Transaction bscscan.com
- analysis Twitter/X Alert twitter.com
- analysis Website reference twitter.com
- analysis Website reference coindesk.com
- analysis Halborn: BurgerSwap Hack halborn.com
- analysis QuillAudits: BurgerSwap Flash Loan Analysis quillhashteam.medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.