BurgerSwap Loses $7.2M as Reentrancy Hits Another Uniswap Fork
BurgerSwap became the fourth protocol in as many weeks to fall to the same category of exploit that had been plaguing the sector since the recent market downturn. Despite the pattern being well established by this point, projects kept shipping contracts with the same underlying weakness.
BurgerSwap's code was largely a copy of Uniswap's, which makes the gap in its implementation particularly notable — raising the question of whether the flaw stemmed from carelessness or something more deliberate.

The numbers
At approximately 3 AM on May 28th (UTC+8), attackers extracted a combined $7.2 million from BurgerSwap across 14 separate transactions. The stolen assets broke down as follows:
- 4,400 WBNB (~$1.6M)
- 22,000 BUSD (~$22K)
- 2.5 ETH (~$6.8K)
- 1.4 million USDT (~$1.4M)
- 432,000 BURGER (~$3.2M)
- 142,000 xBURGER (~$1M)
- 95,000 ROCKS
How each attack ran
Each of the 14 exploit transactions followed a consistent pattern, per analysis credited to @FrankResearcher:
- The attacker took a flash swap of 6,000 WBNB (~$2M) from PancakeSwap.
- Nearly all of that WBNB was swapped for approximately 92,000 BURGER on BurgerSwap.
- The attacker deployed a custom, non-standard BEP-20 token and created a new trading pair pairing 100 units of this fake token against 45,000 BURGER.
- Those 100 fake tokens were then swapped back through the newly created pool for 4,400 WBNB.
- A further swap converted the remaining 45,000 BURGER into another 4,400 WBNB.
- Combining steps 4 and 5, the attacker ended up with 8,800 WBNB.
- 493 WBNB was swapped back into roughly 108,700 BURGER on BurgerSwap.
- The original flash swap was repaid, closing out the transaction at a profit.
Root cause

The exploit hinged on a reentrancy flaw: the attacker was able to trigger a second swap before the pool's reserve values — used to calculate token amounts for swaps — had been updated from the first. This was apparently compounded by the absence of the standard x*y=k invariant check present in the original Uniswap V2 pair contract, which appears to have been dropped from BurgerSwap's implementation. Without that check enforced as x*y>k, an attacker could force a swap of arbitrarily large output while supplying only a minimal amount of input token.
Aftermath
The exploit came amid a broader wave of attacks on BNB Smart Chain protocols over the preceding week, drawing comparisons to a similar cluster of DeFi hacks on Ethereum the previous autumn. Sympathy for BurgerSwap has been limited given the project's direct copying of established code without adequately verifying its security. BurgerSwap stated it was working on a detailed compensation plan for affected users.
Get new scam files the moment we publish them — usually 2–3 emails a week.