T
iTokenly

Spartan Protocol hack — May 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 2, 2021
Target typeDecentralised exchange
Loss$30,000,000Published estimates range $30,000,000 to $40,000,000Price at time of incident
MethodFlash loan attackLP-share payout computed against the live pool balance instead of cached reserves, inflated with flash-loaned WBNB
ChainsBNB Chain
OutcomeProject relaunched

What happened

Spartan Protocol was an automated market maker on BNB Smart Chain built around its SPARTA token. On 1 May 2021 an attacker drained several of its version-one liquidity pools in a short series of transactions funded by a flash loan.

The flaw was in how a pool valued a burned LP token. On liquidity removal the contract computed the holder's share against the pool's live token balance rather than against the cached reserve figures it maintained internally, and it decremented those reserves without re-reading the balances. An attacker could therefore transfer tokens straight into the pool contract, inflating the live balance, then burn LP tokens and be paid out on the inflated number. Amber Group's analysis contrasted this with Uniswap, whose _update() call syncs balances into reserves before the calculation. Halborn describes the exploit as three stages: acquiring pool tokens, inflating the pool's asset balances by transferring tokens in, then burning pool tokens to withdraw a disproportionate share, using multiple transactions to stay under slippage protections. Halborn puts the flash loan at 100,000 WBNB from PancakeSwap. Amber Group, reproducing the attack, reported that repeating the inflate-and-burn cycle twenty times across five transactions was enough to drain about 90 percent of the WBNB in a victim pool.

The transaction Halborn identifies as the exploit was mined in block 7,048,833 at 16:38:39 UTC on 1 May 2021. That timestamp falls just after midnight on 2 May in UTC+8, which is why several accounts date the attack to 2 May.

The size of the loss is disputed. Amber Group and Halborn both put it at roughly $30 million, which reflects what the attacker realised, and this is the figure carried here. Spartan Protocol's own account states that more than $40 million of SPARTA, BNB and other assets were drained from the V1 pools, and dates the attack to 2 May. The team patched the Utils contract over the following days, a first patch having briefly blocked legitimate liquidity removal, then launched a SPARTA V2 token and an upgrade application through which affected holders could claim the SPARTA side of the drained liquidity as compensation.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Transactions

  • 0xb64ae25b0d836c25d115a9368319902c972a0215bd108ae17b1b9617dfb93af8

Attacker addresses

  • 0x3B6e77722e2bBe97C1cfA337B42C0939AEb83671

Sources

  1. Spartan ProtocolPrimary · retrieved 2026-08-01
  2. Amber GroupSecondary · retrieved 2026-08-01
  3. HalbornSecondary · retrieved 2026-08-01
  4. BscScanOn-chain · retrieved 2026-08-01

Official post-mortem: https://spartanprotocol.medium.com/dev-article-may-2021-813a272723ad

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Spartan Protocol hack — May 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/spartan-protocol
https://itokenly.com/hacks/spartan-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.