Spartan Protocol Hack

TOTAL LOST $30.5M
High Flash Loan Attacks BNB Smart Chain

What happened

On May 2, 2021, an attacker exploited flawed liquidity-share accounting in Spartan Protocol's BNB Smart Chain liquidity pools. Using a PancakeSwap flash loan, the attacker manipulated pool balances, minted and burned LP tokens at an inflated redemption value, and drained more than $30 million in SPARTA, BNB, and related assets. The flash loan supplied temporary capital, but the root cause was a smart-contract liquidity-accounting error.

Spartan later patched the calculation and introduced a community compensation process; no full recovery of the attacker's proceeds was confirmed.

Technical Root Cause

`calcLiquidityShare()` read manipulable current pool balances instead of cached accounting balances, allowing temporary balance inflation to inflate an LP redemption.

Case & protocol details

Classification Liquidity-share accounting failure
Protocol Type DEX
Affected asset / contract SPARTA
Smart Contract Language Solidity
Official Website spartanprotocol.org/
Protocol Twitter/X @SpartanProtocol

Attack Timeline

The pool used current token balances when calculating how much a burned LP position could redeem. An attacker temporarily inflated those balances with flash-loaned WBNB and carefully timed swaps and liquidity additions. The contract then treated the attacker's LP tokens as entitled to an outsized portion of the pool.

Repeating this cycle drained real liquidity, after which the flash loan was repaid in the same transaction.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.