T
iTokenly

Value DeFi vSwap hack — May 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 8, 2021
Target typeDecentralised exchange
Loss$11,000,000Price at time of incident
MethodContract logic errorIncorrect enforcement of the weighted constant-product invariant in vSwap pools whose two assets were not weighted 50/50. The invariant check used a power() exponentiation helper that is only correct when its numerator argument is greater than or equal to its denominator argument; swaps crafted to violate that assumption still satisfied the check, letting the attacker withdraw far more value than was put in. Repeated across nine pools.
ChainsBNB Chain
OutcomeUnresolved

What happened

On 7 May 2021 an attacker drained nine liquidity pools on vSwap, the automated market maker operated by Value DeFi on BNB Chain. PeckShield's transaction-level analysis timed the first exploit transaction at 19:41:39 UTC and put the loss at approximately $11 million. Researcher Igor Igamberdiev, who published his own on-chain thread that weekend, gave the same approximate figure.

The bug was arithmetic rather than a stolen key. vSwap supported pools whose two assets were not split 50/50, and for those it enforced a weighted constant-product invariant using a power() exponentiation helper. That helper only returns correct results when its numerator argument is greater than or equal to its denominator argument. By seeding a pool with a dust amount of one token and then swapping in a particular direction, the attacker produced inputs that broke the assumption, so the invariant check passed on trades that removed far more value than they added. The step was repeated across the affected pools, which held BNB, BUSD, BASv2, BDO, MDG, VBOND, BAC, FARM and FIRO.

Published per-asset breakdowns vary and sum to more than the headline number, which is unsurprising given several of the drained tokens were thinly traded and their nominal value overstated what could be realised. The roughly $11 million figure is an estimate; Value DeFi did not publish a post-mortem for this incident.

It was not the project's only loss that week. Igamberdiev put an earlier contract-reinitialisation incident at about $6 million, and Inspex separately documented a drain of 5,345.314 WBNB from Value DeFi's vSafe WBNB vault beginning about half an hour after the vSwap attack, through an unrelated share-calculation flaw. No return of the vSwap funds has been reported.

Sources

  1. PeckShieldSecondary · retrieved 2026-08-01
  2. Igor Igamberdiev (@FrankResearcher)Secondary · retrieved 2026-08-01
  3. CoinGapeSecondary · retrieved 2026-08-01
  4. InspexSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Value DeFi vSwap hack — May 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/value-defi-vswap
https://itokenly.com/hacks/value-defi-vswap

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.