T
iTokenly

SurgeBNB (xSurge) hack — August 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedAugust 16, 2021
Target typeToken contract
Loss$5,000,000Price at time of incident
MethodReentrancyThe SurgeBNB token contract acted as its own market maker. Its sell path transferred BNB to the seller before updating supply and balance state, so a contract-based seller could re-enter via its fallback function and buy SURGE back at the stale pre-update price. Funded by a 10,000 BNB flash loan, the attacker repeated the buy-sell-buy cycle several times before liquidating.
ChainsBNB Chain
OutcomeUnresolved

What happened

SurgeBNB was one of several "Surge" tokens issued by xSurge on BNB Chain. Its contract acted as its own market: buyers sent BNB to the contract to mint SURGE, and sellers called a sell function that paid BNB back out of the contract's reserve.

On 16 August 2021 an attacker exploited a re-entrancy flaw in that sell path. The contract sent BNB to the seller before updating its own supply and balance state, so a contract-based seller could re-enter through its fallback function and buy SURGE back at the stale, pre-update price. Funded by a 10,000 BNB flash loan in the first round, the attacker repeated the buy-sell-buy cycle several times, accumulating SURGE far below the price the contract believed it was quoting, and then liquidated the position. One of the exploit transactions is timestamped on BscScan at 16 August 2021, 19:40 UTC, sent from an address labelled XSURGE Exploiter 1.

Independent write-ups by Knownsec Blockchain Lab and by Beosin, the latter published in English via Odaily, both put the loss at roughly $5 million; Beosin traced the attacker's profit at more than 13,111 BNB.

The SurgeBNB contract was immutable and could not be patched. xSurge published a security alert dated 16 August 2021 telling holders to sell their SurgeBNB immediately through the contract's write function on BscScan, stating that the vulnerability did not affect the SurgeUSD and SurgeETH contracts and that SurgeBNB would be re-released only after a full audit was completed. The alert did not disclose a loss figure. The stolen BNB was never returned and no arrests have been reported.

Sources

  1. xSurge (SurgeBNB Security Vulnerability Alert)Primary · retrieved 2026-08-01
  2. Knownsec Blockchain LabSecondary · retrieved 2026-08-01
  3. Odaily (Beosin analysis)Secondary · retrieved 2026-08-01
  4. BscScanOn-chain · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "SurgeBNB (xSurge) hack — August 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/surgebnb
https://itokenly.com/hacks/surgebnb

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.