{"investigation":{"slug":"burgerswap","entity_name":"BurgerSwap","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"BurgerSwap is a decentralized exchange (DEX) and automated market maker (AMM) protocol launched in September 2020 on Binance Smart Chain (BSC), built around the native BURGER governance token. On May 28, 2021, the protocol suffered a flash loan and reentrancy exploit that drained approximately $7.2 million in user funds across 14 transactions. Uniswap founder Hayden Adams publicly noted that a critical line of code enforcing the constant-product formula had been deliberately removed from BurgerSwap's fork of Uniswap v2, raising allegations of an intentional vulnerability or insider involvement by the anonymous development team.","sections":[{"content":"BurgerSwap is an automated market maker and decentralized exchange protocol deployed on Binance Smart Chain (BSC). It launched in September 2020 and is built on an implementation of the ERC-2917 standard, which was co-initiated by Tony Carson, Dr. Mehmet Sabir Kiraz, and Dr. Suleyman Kardas. The project's native token, BURGER, functions as both a governance token and a liquidity-mining reward instrument. Binance founder Changpeng Zhao (CZ) publicly stated he did not know who built the protocol at the time of its launch, highlighting the project's lack of transparent team disclosure. BurgerSwap is architecturally derived from Uniswap v2 but introduced modifications that, as later demonstrated, removed a critical security invariant. The project subsequently rebranded as BurgerCities in 2022, pivoting toward a Web3 metaverse product that combines DeFi and NFT functionality.","heading":"Overview","sources":[{"url":"https://cryptopotato.com/who-is-behind-burgerswap-already-400-million-bnb-staked-in-1-day-via-binance-smart-chain/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/burgerswap-frying-high-binance-offers-up-the-latest-dish-on-defi-menu","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://academy.binance.com/en/articles/what-is-burgercities-burger","name":"academy.binance.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On May 28, 2021, at approximately 03:00 UTC+8, BurgerSwap was exploited in a combined flash loan and reentrancy attack spanning 14 transactions, resulting in the theft of approximately $7.2 million in user assets. The attacker initiated the attack by borrowing 6,000 WBNB (approximately $2 million at the time) from PancakeSwap via a flash loan. The attacker then swapped the WBNB for approximately 92,000 BURGER tokens on BurgerSwap. A malicious BEP-20 token (colloquially referred to as 'Fake Coin') was created and a trading pair with BURGER was established, seeded with 100 fake tokens and approximately 45,000 BURGER. By routing trades through the BURGER -> Fake Coin -> WBNB path, the attacker was able to exploit a reentrancy vulnerability: because the attacker controlled the fake token contract, the _innerTransferFrom function called into the attacker's contract during token transfers. This allowed re-entry into the swapExactTokensForTokens function before reserve values were updated, enabling the attacker to manipulate the protocol's internal price calculations and extract excess funds. The attack was made possible because BurgerSwap's Pair contract did not independently verify swap calculations from the Platform layer, relying entirely on data that could be manipulated through reentrancy. The total assets stolen were: 4,400 WBNB (~$1.6 million), 1.4 million USDT (~$1.4 million), 432,000 BURGER (~$3.2 million), 142,000 xBURGER (~$1 million), 22,000 BUSD (~$22,000), 2.5 ETH (~$6,800), and 95,000 ROCKS. BURGER's price dropped approximately 27% in the immediate aftermath, falling from $9.24 to $6.75.","heading":"May 2021 Flash Loan and Reentrancy Exploit","sources":[{"url":"https://halborn.com/explained-the-burgerswap-hack-may-2021/","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2021/05/28/burgerswap-hit-by-flash-loan-attack-netting-over-7m","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/another-bsc-project-exploit-7-2m-drained-from-burgerswap-in-a-flash-loan-attack/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/an-analysis-of-the-attack-on-burgerswap-e48968040bad","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/binance-smart-chain-defi-project-burgerswap-hacked-for-7-million/","name":"cryptoslate.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security analysis of the BurgerSwap exploit identified that the protocol, as a fork of Uniswap v2, had removed the single line of code that enforces the constant-product formula (x*y=k) within its core contract. Uniswap founder Hayden Adams publicly commented: 'This thread sounds complicated. Here's what happened very simply. Uniswap v2 fork removed the only line that enforces x*y=k from core,' adding sarcastically 'iWoNDerWhYTHeyDiDtHAt.' This implied the omission was intentional rather than accidental, as the line in question is a well-understood and foundational security requirement in AMM design. Without this invariant, the core contract could be 'trivially drained.' The removal enabled the attacker to execute two separate transfers where the protocol should have permitted only one. Security firm SlowMist's post-incident analysis confirmed that the Pair layer 'fully trusted the data from the Platform layer and did not do its own check,' and that re-entry during _update() calls allowed the attacker to manipulate reserve values before they were synchronized. Beosin, a blockchain security firm, had audited the first version of BurgerSwap in September 2020, but the project had initially relied on internal team audits and was reportedly offering a 1,000 BNB bounty to outside auditors. PeckShield later noted that the exploit reflected a logic flaw at the architecture level rather than a simple coding error. Because BurgerSwap's team was anonymous at the time of launch and the omitted line was critical and well-known in DeFi security, allegations of deliberate insider involvement were raised by community members and media; these allegations remain unverified and no attribution has been established by law enforcement or blockchain forensics firms.","heading":"Root Cause: Removed Security Invariant and Insider Allegations","sources":[{"url":"https://cryptobriefing.com/7-million-lost-flash-loan-attack-bsc-burgerswap/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/an-analysis-of-the-attack-on-burgerswap-e48968040bad","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://blockcast.cc/news/peckshield-brief-analysis-of-burgerswap-lightning-loan-attack-the-logic-behind-the-defi-protocol-is-more-important-than-the-code/","name":"blockcast.cc","type":"other","credibility":3},{"url":"https://halborn.com/explained-the-burgerswap-hack-may-2021/","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit was confirmed on-chain via Binance Smart Chain. SlowMist's analysis identified one of the attack's representative transactions as: 0xac8a739c1f668b13d065d56a03c37a686e0aa1c9339e79fcbc5a2d0a6311e333. The attack spanned 14 discrete transactions. The flash loan source was PancakeSwap's WBNB liquidity pool. The attacker's specific BSC wallet address and the full transaction cluster were not publicly disclosed in available security reports as of this writing, and no verified on-chain attribution linking the exploit to a named individual or group has been published by a credible blockchain analytics firm. The BurgerSwap contract address referenced in BSCScan records is 0x3f820d0bd7ce1cc0a993325cd46cae870a8d8bdc. The exploit occurred at block height 7781159 on BSC. No funds have been publicly reported as recovered or returned by the attacker.","heading":"On-Chain Evidence","sources":[{"url":"https://slowmist.medium.com/an-analysis-of-the-attack-on-burgerswap-e48968040bad","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://bscscan.com/address/0x3f820d0bd7ce1cc0a993325cd46cae870a8d8bdc","name":"bscscan.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/another-bsc-project-exploit-7-2m-drained-from-burgerswap-in-a-flash-loan-attack/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"BurgerSwap's development team was not publicly identified at the time of launch. Binance CEO Changpeng Zhao stated publicly that he did not know who built the protocol. The ERC-2917 standard underlying the project was co-authored by Tony Carson, Dr. Mehmet Sabir Kiraz, and Dr. Suleyman Kardas — individuals with documented blockchain research backgrounds — but their direct roles in building and operating BurgerSwap's smart contracts were not confirmed in primary sources. The team is reported to span the US, UK, China, and Turkey. Ryan Fang, a co-founder of Ankr Network, is listed as an advisor. The anonymous launch structure, combined with the subsequent exploit and disputed code omission, drew comparisons to other BSC-era projects later found to have conducted deliberate exit schemes. No formal legal action, regulatory finding, or law enforcement attribution has been publicly recorded against BurgerSwap's operators.","heading":"Team Background and Transparency","sources":[{"url":"https://cryptopotato.com/who-is-behind-burgerswap-already-400-million-bnb-staked-in-1-day-via-binance-smart-chain/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/7-million-lost-flash-loan-attack-bsc-burgerswap/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://research.binance.com/en/projects/burger-swap","name":"research.binance.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, BurgerSwap suspended protocol services and issued a public statement acknowledging the attack and promising to 'work hard to cover users' loss.' The team subsequently published a 'Go Forward Plan' detailing a compensation mechanism: a new token, cBURGER, would be airdropped to users who held affected liquidity pool tokens at block height 7781159 (immediately prior to the exploit on May 27, 2021). The cBURGER compensation pool was announced to contain BURGER worth approximately $7 million, funded through newly issued BURGER tokens. Compensation was to be distributed over 90 days in linear proportion through a staking mechanism, where eligible users could stake cBURGER to receive BURGER rewards. The decision to fund compensation via newly minted tokens was noted as potentially dilutive to existing BURGER holders. No independent confirmation of full compensation distribution has been published by a neutral third party.","heading":"Post-Exploit Response and Compensation","sources":[{"url":"https://medium.com/burgerswapblog/go-forward-plan-cburger-d522219affae","name":"medium.com","type":"other","credibility":3},{"url":"https://u.today/binance-smart-chains-burgerswap-suffers-72-million-exploit","name":"u.today","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the 2021 exploit, BurgerSwap underwent significant restructuring. In early 2022, the project rebranded as BurgerCities, pivoting from a pure DeFi/DEX model to a Web3 metaverse platform combining DeFi, NFT, and gaming elements. The alpha version of BurgerCities launched in summer 2022 with over 100 announced partners. In August 2022, the maximum supply of BURGER tokens was tripled from 21 million to 63 million, a change the team attributed to governance approval but which was described as controversial within the community. The BURGER token has continued to trade on exchanges including Binance, HTX, and CoinEx following the rebrand. No new major security incidents have been reported as of the date of this investigation, though the project's relevance and trading volume have declined substantially from its 2020-2021 peak.","heading":"Rebranding and Subsequent Activity","sources":[{"url":"https://medium.com/burgerswapblog/go-forward-plan-cburger-d522219affae","name":"medium.com","type":"other","credibility":3},{"url":"https://academy.binance.com/en/articles/what-is-burgercities-burger","name":"academy.binance.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/burger-cities/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://www.fxcm.com/markets/insights/everything-you-need-to-know-about-burgercities/","name":"fxcm.com","type":"other","credibility":3}],"severity":"medium"},{"content":"BurgerSwap carries a high baseline risk profile based on the following documented factors. First, the protocol suffered a critical exploit resulting in approximately $7.2 million in confirmed user losses, with no verified recovery of stolen funds. Second, Uniswap founder Hayden Adams publicly stated that a fundamental security invariant (the x*y=k constant product formula) was removed from the protocol's core code — a modification that security researchers characterized as trivially exploitable and that raised unresolved allegations of deliberate insider action. Third, the project launched and operated under an anonymous team with limited public accountability, a pattern associated with elevated fraud risk in the BSC DeFi ecosystem of 2020-2021. Fourth, the post-exploit compensation mechanism relied on newly minted tokens, representing dilution rather than restitution from existing reserves or recovered funds. Fifth, the project's subsequent pivot and token supply tripling in 2022 may indicate structural changes to tokenomics that further disadvantaged early users. ZachXBT, an established on-chain investigator, has flagged BurgerSwap as a notable entity of concern. Users considering interaction with BurgerSwap or BurgerCities contracts should exercise extreme caution. The original exploit contracts remain deployed on BSC.","heading":"Risk Assessment","sources":[{"url":"https://cryptobriefing.com/7-million-lost-flash-loan-attack-bsc-burgerswap/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://halborn.com/explained-the-burgerswap-hack-may-2021/","name":"halborn.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/an-analysis-of-the-attack-on-burgerswap-e48968040bad","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2021/05/28/burgerswap-hit-by-flash-loan-attack-netting-over-7m","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09","event":"BurgerSwap launches on Binance Smart Chain with the BURGER governance token.","source":"","date_original":"2020-09-01"},{"date":"2020-09","event":"Beosin audits the first version of BurgerSwap smart contracts. Team relies primarily on internal audits and offers 1,000 BNB bounty for external review.","source":"","date_original":"2020-09-01"},{"date":"2021-05-28","event":"Flash loan and reentrancy exploit drains approximately $7.2 million from BurgerSwap across 14 transactions on BSC. BURGER token price drops ~27%.","source":""},{"date":"2021-05-28","event":"Uniswap founder Hayden Adams publicly states BurgerSwap removed the only code line enforcing x*y=k from its Uniswap v2 fork, implying the vulnerability may have been intentional.","source":""},{"date":"2021-05-28","event":"BurgerSwap suspends protocol services and issues statement promising to cover user losses.","source":""},{"date":"2021-05-29","event":"SlowMist and PeckShield publish technical post-mortems confirming reentrancy vulnerability and missing constant-product formula enforcement.","source":""},{"date":"2021-06","event":"BurgerSwap publishes Go Forward Plan detailing cBURGER compensation token airdrop over 90-day linear distribution for affected liquidity providers.","source":"","date_original":"2021-06-01"},{"date":"2022","event":"BurgerCities metaverse platform launches in alpha, marking effective rebranding from BurgerSwap.","source":"","date_original":"2022-01-01"},{"date":"2022-08","event":"Maximum BURGER token supply tripled from 21 million to 63 million via governance decision, described as controversial by community members.","source":"","date_original":"2022-08-01"}],"sources_used":[{"url":"https://cryptopotato.com/who-is-behind-burgerswap-already-400-million-bnb-staked-in-1-day-via-binance-smart-chain/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260611191149/https://cryptopotato.com/who-is-behind-burgerswap-already-400-million-bnb-staked-in-1-day-via-binance-smart-chain/","credibility":3,"archive_timestamp":"2026-06-11T19:11:49+00:00"},{"url":"https://cointelegraph.com/news/burgerswap-frying-high-binance-offers-up-the-latest-dish-on-defi-menu","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260124201657/https://cointelegraph.com/news/burgerswap-frying-high-binance-offers-up-the-latest-dish-on-defi-menu","credibility":3,"archive_timestamp":"2026-01-24T20:16:57+00:00"},{"url":"https://academy.binance.com/en/articles/what-is-burgercities-burger","name":"academy.binance.com","type":"other","archive_url":"http://web.archive.org/web/20250910103406/https://academy.binance.com/en/articles/what-is-burgercities-burger","credibility":3,"archive_timestamp":"2025-09-10T10:34:06+00:00"},{"url":"https://halborn.com/explained-the-burgerswap-hack-may-2021/","name":"halborn.com","type":"other","archive_url":"https://web.archive.org/web/20260830085815/https://www.halborn.com/blog/post/explained-the-burgerswap-hack-may-2021","credibility":3,"archive_timestamp":"2026-08-30T08:58:15+00:00"},{"url":"https://www.coindesk.com/markets/2021/05/28/burgerswap-hit-by-flash-loan-attack-netting-over-7m","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260725040603/https://www.coindesk.com/markets/2021/05/28/burgerswap-hit-by-flash-loan-attack-netting-over-7m","credibility":3,"archive_timestamp":"2026-07-25T04:06:03+00:00"},{"url":"https://cryptopotato.com/another-bsc-project-exploit-7-2m-drained-from-burgerswap-in-a-flash-loan-attack/","name":"cryptopotato.com","type":"other","archive_url":"https://web.archive.org/web/20260830125431/https://cryptopotato.com/another-bsc-project-exploit-7-2m-drained-from-burgerswap-in-a-flash-loan-attack/","credibility":3,"archive_timestamp":"2026-08-30T12:54:31+00:00"},{"url":"https://slowmist.medium.com/an-analysis-of-the-attack-on-burgerswap-e48968040bad","name":"slowmist.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250909123100/https://slowmist.medium.com/an-analysis-of-the-attack-on-burgerswap-e48968040bad","credibility":3,"archive_timestamp":"2025-09-09T12:31:00+00:00"},{"url":"https://cryptoslate.com/binance-smart-chain-defi-project-burgerswap-hacked-for-7-million/","name":"cryptoslate.com","type":"other","archive_url":"https://web.archive.org/web/20260830125613/https://cryptoslate.com/binance-smart-chain-defi-project-burgerswap-hacked-for-7-million/","credibility":3,"archive_timestamp":"2026-08-30T12:56:13+00:00"},{"url":"https://cryptobriefing.com/7-million-lost-flash-loan-attack-bsc-burgerswap/","name":"cryptobriefing.com","type":"other","archive_url":"https://web.archive.org/web/20260830162813/https://cryptobriefing.com/7-million-lost-flash-loan-attack-bsc-burgerswap/","credibility":3,"archive_timestamp":"2026-08-30T16:28:13+00:00"},{"url":"https://blockcast.cc/news/peckshield-brief-analysis-of-burgerswap-lightning-loan-attack-the-logic-behind-the-defi-protocol-is-more-important-than-the-code/","name":"blockcast.cc","type":"other","archive_url":"https://web.archive.org/web/20260901071554/https://blockcast.cc/peckshield-brief-analysis-of-burgerswap-lightning-loan-attack-the-logic-behind-the-defi-protocol-is-more-important-than-the-code/","credibility":3,"archive_timestamp":"2026-09-01T07:15:54+00:00"},{"url":"https://bscscan.com/address/0x3f820d0bd7ce1cc0a993325cd46cae870a8d8bdc","name":"bscscan.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://research.binance.com/en/projects/burger-swap","name":"research.binance.com","type":"other","archive_url":"https://web.archive.org/web/20260830091513/https://www.binance.com/en/research/projects/burger-swap","credibility":3,"archive_timestamp":"2026-08-30T09:15:13+00:00"},{"url":"https://medium.com/burgerswapblog/go-forward-plan-cburger-d522219affae","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://u.today/binance-smart-chains-burgerswap-suffers-72-million-exploit","name":"u.today","type":"other","archive_url":"https://web.archive.org/web/20260830091649/https://u.today/price-analysis/xrp-shiba-inu-shib-stellar-xlm-and-bitcoin-btc-price-analysis-for-august-28-moment-where-bulls","credibility":3,"archive_timestamp":"2026-08-30T09:16:49+00:00"},{"url":"https://coinmarketcap.com/currencies/burger-cities/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260301135619/https://coinmarketcap.com/currencies/burger-cities/","credibility":3,"archive_timestamp":"2026-03-01T13:56:19+00:00"},{"url":"https://www.fxcm.com/markets/insights/everything-you-need-to-know-about-burgercities/","name":"fxcm.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:56.943866+00:00","updated_at":"2026-09-01T07:26:08.816231+00:00"}}