Uranium Finance Hack

TOTAL LOST $57.2M
High Arithmetic Overflow & Underflow Attacks BNB Chain (BSC)

What happened

Uranium Finance was a BNB Chain automated market maker whose v2 pair contracts contained a broken constant-product invariant check. On April 28, 2021, the flaw was used to drain liquidity from 26 pools.

Technical Root Cause

A copied Uniswap V2 pair implementation used inconsistent scaling constants in its fee-adjusted reserve calculation and its K-invariant check, so swaps could pass without preserving the intended constant-product constraint.

Case & protocol details

Classification AMM constant-product invariant failure
Protocol Type Exploit/Other
Affected asset / contract sRADS, U92, RADS
Smart Contract Language Solidity
Official Website uranium.finance/
Protocol Twitter/X @UraniumFinance

Attack Timeline

The v2 migration changed the balance-adjustment multiplier from 1,000 to 10,000 but left the comparison side of the K invariant at 1,000 squared. That mismatch let a caller send a trivial amount of an input token, call swap, and withdraw most of the output reserve. The attacker repeated the pattern across 26 pools.

Funds Recovery

54.2%

Recovered

$31.0M

Net Loss

$26,197,600

Post-Incident Timeline

  • 2025-02-24

    SDNY and @HSISanDiego  seize cryptocurrency worth approximately $31 million related to April 2021 hack of Uranium Finance.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.