XSURGE Hack
What happened
In August 2021, an attacker used a 10,000 BNB flash loan to exploit a reentrancy and state-ordering flaw in SurgeBNB's buy/sell flow on BNB Chain. Repeated transactions drained roughly 13,112 BNB, reported at about $5M–$5.57M.
SurgeBNB violated checks-effects-interactions around a price-sensitive sell/buy sequence. External code could run before relevant supply and accounting state was finalized, enabling a cross-function reentrancy and stale-state pricing effect.
Case & protocol details
Attack Timeline
The vulnerable sell flow performed an external interaction while price-sensitive supply and accounting state was not yet finalized. The attacker flash-borrowed BNB, bought SURGE, then used the stale state in a reentrant sell/buy sequence to obtain an advantageous token price and cash out BNB. Technical analysis describes the pattern as repeated across multiple transactions.
The record does not claim a verified recovered amount or retain an unsupported assertion that proceeds used a particular bridge route; available evidence supports subsequent transfers reaching Binance.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
- report Post-mortem medium.com
- transaction Transaction bscscan.com
- analysis SlowMist BSC incident record hacked.slowmist.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.