T
iTokenly

Meerkat Finance hack — March 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeOther
Loss$31,000,000Price at time of incident
MethodAccess control flawupgradeable vault proxies re-pointed to a draining implementation using owner/deployer privileges
ChainsBNB Chain
Attributed toMeerkat Finance's own deployer account; pseudonymous developer 'Jamboo' said the team invited a third party to attack the contractSuspected
OutcomeUnresolved

What happened

Meerkat Finance was a yield-vault protocol on BNB Smart Chain that had launched roughly a day earlier. On 4 March 2021 its vaults were emptied of 73,653 BNB and about 13.96 million BUSD, worth roughly $31 million at the time.

The drain was executed by re-pointing the project's upgradeable vault proxies at a new implementation contract and then calling it to move the deposits out. CoinDesk reported that on-chain data pointed to the original Meerkat deployer's account being used to alter the contract, and noted that unless the project's private key had been compromised this suggested the drain was carried out by Meerkat itself. A later technical write-up by Vidma Security describes the deployer calling upgradeTo() twice and taking ownership of two vaults through a permissionless initialization process, while also noting a post-mortem that pointed to a compromised private key. Meerkat's website and Twitter account went offline the same day.

The project told users on Telegram that its vaults had been compromised by an outside attacker. Two days later an account identifying itself as the developer 'Jamboo' said the team had invited a third party to attack the vulnerability, described the episode as a test of user greed, and promised a full report and a refund. Jamboo authenticated the claim by sending a transaction from the Meerkat deployer contract. No report was published.

The incident is commonly described as a rug pull rather than an external hack, but that characterisation rests on on-chain inference and the developer's own ambiguous statement. No charges, conviction or formal government attribution has been reported. Because BNB Smart Chain's main on- and off-ramps run through Binance, the exchange said its joint security team was monitoring the situation and would freeze any stolen funds that reached it. Whether users were ultimately made whole is unsettled: several secondary accounts state that Binance-assisted recovery returned roughly $30 million, but this could not be confirmed from a primary or tier-1 source and none of the sources cited here addresses the outcome.

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. Vidma SecuritySecondary · retrieved 2026-08-01
  4. crypto.security (Marin Ivezic)Secondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Meerkat Finance hack — March 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/meerkat-finance
https://itokenly.com/hacks/meerkat-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.