T
iTokenly

BurgerSwap hack — May 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeDecentralised exchange
Loss$7,200,000Published estimates range $7,000,000 to $7,200,000Price at time of incident
MethodReentrancyThe attacker deployed a counterfeit BEP-20 token and created a trading pair between it and BURGER. BurgerSwap was a Uniswap V2 fork from which a validation check present in the original code had been removed, so the exchange accepted swap instructions it should have rejected. The fake token's transfer logic re-entered the exchange mid-swap, letting a flash-loaned position be swapped against the pair twice; in one instance 6,000 WBNB was returned as 8,800 WBNB. The loop was repeated across 14 transactions.
ChainsBNB Chain
OutcomeUsers reimbursed

What happened

BurgerSwap, an automated market maker on BNB Chain forked from Uniswap V2, was drained on 27 May 2021 across 14 transactions. The project's own compensation notice pins the pre-attack snapshot at block 7781159, timestamped 18:54:46 UTC that day; Decrypt, reporting on BurgerSwap's post-mortem, placed the attack at about 21:00 UTC. Much coverage dates the incident to 28 May, the day it was reported.

The attacker deployed a counterfeit BEP-20 token and created a trading pair between it and BURGER. Because BurgerSwap's fork had dropped a validation check present in the original Uniswap V2 code, a point publicised by Uniswap founder Hayden Adams and reported by The Block, the exchange accepted swap instructions it should have rejected, and a single flash-loaned position could be swapped against the pair twice: in one example 6,000 wrapped BNB came back as 8,800. Repeating the loop distorted the BURGER price and emptied reserves.

Figures vary. BurgerSwap first put the loss at around $7 million; most reporting, including CoinDesk and The Block, settled on $7.2 million. Decrypt's breakdown of the stolen assets gives $3.2 million in BURGER, $1.6 million in wrapped BNB, $1.4 million in Tether and $1 million in xBURGER, alongside $152,000 in ROCKS, $22,000 in BUSD and $6,800 in ETH. The Block reported that the attacker used the Nerve protocol to sell the tokens and move the proceeds to Ethereum.

BurgerSwap issued a compensation token, cBURGER, claimable in proportion to direct losses by holders of the affected liquidity pairs at the time of the attack and redeemable by staking into a pool that releases BURGER linearly over 90 days. The attacker was never identified.

Sources

  1. BurgerCities (BurgerSwap)Primary · retrieved 2026-08-01
  2. DecryptSecondary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01
  4. CoinDeskSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "BurgerSwap hack — May 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/burgerswap
https://itokenly.com/hacks/burgerswap

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.