Partager cet article

Binance Chain DeFi Exchange Uranium Finance Loses $50M in Exploit

So far, only $9 million in ETH and BTC from the hacker's haul has made it off the Binance Smart Chain blockchain.

Mise à jour 14 sept. 2021, 12:48 p.m. Publié 28 avr. 2021, 4:27 p.m. Traduit par IA
jwp-player-placeholder

A Binance Smart Chain Uniswap clone, Uranium Finance, lost $50 million in tokens early Wednesday morning in an exploit.

STORY CONTINUES BELOW
Ne manquez pas une autre histoire.Abonnez vous à la newsletter Crypto Daybook Americas aujourd. Voir toutes les newsletters

The attacker took advantage of a vulnerability that has been present in Uranium's v2 contracts since the exchange upgraded over a week ago. After sending the minimum required tokens into Uranium's "pair contracts," the attacker drained the liquidity pools for multiple token pairs; a misplaced zero in the contract's balance field (or rather, the lack of one in a section that manages reserves) created the opening for the attack vector.

Out of the $50 million filched, pools for Binance's blockchain token and its stablecoin (BUSD) each lost $18 million in funds. Ethereum and BTCB pools (Binance Chain's version of "wrapped'' bitcoin) collectively lost around $9 million worth of tokens. An additional $6.7 million in USDT and $1.7 million in DOT, ADA and Uranium's own token also disappeared from other pools.

Read more: SushiSwap, Fleeing Ethereum Fees, Is Now Live on Binance Smart Chain, Fantom, Others

Post-hack, the BTCB has been swapped for real BTC, and the ETH is in an Ethereum mixer called Tornado Cash, according to The Block researcher Igor Igamberdiev.

Notably, per a past exploit on Binance's BSC blockchain, the BNB and BUSD could be recovered through a rollback, though Binance has made no announcements on the matter.

'Whole farm at risk'

This vulnerability is present in all Uranium v2 pools. A Telegram pinned message by anonymous Uranium community member Baymax warns users to "STOP adding liquidity ... and remove liquidity if you can" because the exploit still leaves millions of dollars in tokens at risk in these v2 contracts.

Baymax advises users to migrate to the v2.1 contracts, which include a fix for the vulnerability. Notably, the attack came two hours before v2.1 went live, even though the exploit had been open since Uranium's last upgrade to v2 just over a week ago.

Read more: PancakeSwap Widens Binance Smart Chain’s Lead Over Ethereum on Transactions

"As you all know, we commissioned an audit, and among the finding was an issue of low severity. Devs dug deeper and found an issue that had the whole farm at risk,” Baymax's pinned message reads.

"There are a total of 7 people in Uranium who knew of the exploit. Outside of Uranium would be the 3 auditors contractors and their respective sub cons who may be aware of this flaw," it reads farther down. Later in the message, Baymax hypothesizes that "someone leaked information" that lead to the attacker exploiting the vulnerability.

Baymax did not respond to follow-up questions regarding the auditor of Uranium’s code.

Baymax also denied any involvement with Uranium beyond being a "community member" when speaking with CoinDesk. No other "community members," whether part of Uranium's core team or otherwise, responded by press time.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

XRP Ledger Upgrade Lays Groundwork for Lending, Tokenization Expansion

XRP symbol on top of dollar bills. (Unsplash/CoinDesk)

One of the amendments in the new release corrects an accounting error affecting Multi-Purpose Tokens (MPTs) held in escrow.

What to know:

  • The XRP Ledger released version 3.0.0 of its server software, rippled, focusing on amendments, bug fixes and improving accounting accuracy and protocol extensibility.
  • Operators must upgrade to the new version to maintain network compatibility because the update addresses ledger inconsistencies and prepares for future upgrades.
  • Key changes include fixing token escrow accounting errors, enhancing consensus stall detection and tightening security measures, which are crucial for XRPL's expansion into tokenization and DeFi.