Uranium Finance Hack
What happened
Uranium Finance was a BNB Chain automated market maker whose v2 pair contracts contained a broken constant-product invariant check. On April 28, 2021, the flaw was used to drain liquidity from 26 pools.
A copied Uniswap V2 pair implementation used inconsistent scaling constants in its fee-adjusted reserve calculation and its K-invariant check, so swaps could pass without preserving the intended constant-product constraint.
Case & protocol details
Attack Timeline
The v2 migration changed the balance-adjustment multiplier from 1,000 to 10,000 but left the comparison side of the K invariant at 1,000 squared. That mismatch let a caller send a trivial amount of an input token, call swap, and withdraw most of the output reserve. The attacker repeated the pattern across 26 pools.
Funds Recovery
Recovered
$31.0M
Net Loss
$26,197,600
Post-Incident Timeline
-
2025-02-24
SDNY and @HSISanDiego seize cryptocurrency worth approximately $31 million related to April 2021 hack of Uranium Finance.
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Post-mortem rekt.news
- transaction Transaction bscscan.com
- analysis Twitter/X Alert twitter.com
- analysis Web Archive web.archive.org
- analysis Website reference uraniumfinance.medium.com
- analysis Website reference twitter.com
- analysis Hack Analysis: Uranium Finance, April 2021 immunefi.com
- analysis Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks justice.gov
- analysis Uranium - Learn EVM Attacks coinspect.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.