XSURGE Hack

TOTAL LOST $5.6M
Medium Flash Loan Attacks bsc

What happened

In August 2021, an attacker used a 10,000 BNB flash loan to exploit a reentrancy and state-ordering flaw in SurgeBNB's buy/sell flow on BNB Chain. Repeated transactions drained roughly 13,112 BNB, reported at about $5M–$5.57M.

Technical Root Cause

SurgeBNB violated checks-effects-interactions around a price-sensitive sell/buy sequence. External code could run before relevant supply and accounting state was finalized, enabling a cross-function reentrancy and stale-state pricing effect.

Case & protocol details

Classification Protocol Logic / Reentrancy
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract SURGE
Official Website surge.ddns.net/
Protocol Twitter/X @SurgeTokenBSC?s=09

Attack Timeline

The vulnerable sell flow performed an external interaction while price-sensitive supply and accounting state was not yet finalized. The attacker flash-borrowed BNB, bought SURGE, then used the stale state in a reentrant sell/buy sequence to obtain an advantageous token price and cash out BNB. Technical analysis describes the pattern as repeated across multiple transactions.

The record does not claim a verified recovered amount or retain an unsupported assertion that proceeds used a particular bridge route; available evidence supports subsequent transfers reaching Binance.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.