Binance Chain DeFi Exchange Uranium Finance Loses $50M in Exploit
So far, only $9 million in ETH and BTC from the hacker's haul has made it off the Binance Smart Chain blockchain.
A Binance Smart Chain Uniswap clone, Uranium Finance, lost $50 million in tokens early Wednesday morning in an exploit.
The attacker took advantage of a vulnerability that has been present in Uranium's v2 contracts since the exchange upgraded over a week ago. After sending the minimum required tokens into Uranium's "pair contracts," the attacker drained the liquidity pools for multiple token pairs; a misplaced zero in the contract's balance field (or rather, the lack of one in a section that manages reserves) created the opening for the attack vector.
4/10
— Igor Igamberdiev (@FrankResearcher) April 28, 2021
What was the exploit?
Pair contracts in Uranium v2 had a bug due to which anyone could interact with them and withdraw almost all tokens due to a calculation error.
The balances of pair contracts during sanity checks were a hundred times larger than the real ones. pic.twitter.com/OwBkcrhP8f
Out of the $50 million filched, pools for Binance's blockchain token
Read more: SushiSwap, Fleeing Ethereum Fees, Is Now Live on Binance Smart Chain, Fantom, Others
Post-hack, the BTCB has been swapped for real BTC, and the ETH is in an Ethereum mixer called Tornado Cash, according to The Block researcher Igor Igamberdiev.
Notably, per a past exploit on Binance's BSC blockchain, the BNB and BUSD could be recovered through a rollback, though Binance has made no announcements on the matter.
'Whole farm at risk'
This vulnerability is present in all Uranium v2 pools. A Telegram pinned message by anonymous Uranium community member Baymax warns users to "STOP adding liquidity ... and remove liquidity if you can" because the exploit still leaves millions of dollars in tokens at risk in these v2 contracts.
Baymax advises users to migrate to the v2.1 contracts, which include a fix for the vulnerability. Notably, the attack came two hours before v2.1 went live, even though the exploit had been open since Uranium's last upgrade to v2 just over a week ago.
Read more: PancakeSwap Widens Binance Smart Chain’s Lead Over Ethereum on Transactions
"As you all know, we commissioned an audit, and among the finding was an issue of low severity. Devs dug deeper and found an issue that had the whole farm at risk,” Baymax's pinned message reads.
"There are a total of 7 people in Uranium who knew of the exploit. Outside of Uranium would be the 3 auditors contractors and their respective sub cons who may be aware of this flaw," it reads farther down. Later in the message, Baymax hypothesizes that "someone leaked information" that lead to the attacker exploiting the vulnerability.
Baymax did not respond to follow-up questions regarding the auditor of Uranium’s code.
Baymax also denied any involvement with Uranium beyond being a "community member" when speaking with CoinDesk. No other "community members," whether part of Uranium's core team or otherwise, responded by press time.
More For You
Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.
What to know:
Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.
The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.
More For You
Weaker dollar fails to spur bitcoin gains, but there's a reason for that, JPMorgan says

Gold and other hard assets are rallying on dollar weakness, but bitcoin is lagging as markets continue to treat it as a liquidity-sensitive risk asset.
What to know:
- Bitcoin has, unusually, not rallied alongside the slide in the U.S. dollar.
- JPMorgan strategists say the dollar’s weakness is being driven by short-term flows and sentiment, not changes in growth or monetary policy expectations, and they expect the currency to stabilize as the U.S. economy strengthens.
- Because markets do not view the current dollar decline as a lasting macro shift, bitcoin is trading more like a liquidity-sensitive risk asset than a reliable dollar hedge, leaving gold and emerging markets as the preferred beneficiaries of dollar diversification.












