{"investigation":{"slug":"spartan","entity_name":"Spartan Protocol","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.85,"status":"published","content_type":"investigation","summary":"Spartan Protocol is a decentralized liquidity and synthetic-asset protocol that launched on Binance Smart Chain (BSC) in 2020 and was operated by a fully anonymous, community-driven team. On May 2, 2021, a critical vulnerability in the protocol's liquidity-share calculation logic was exploited via flash loan, resulting in approximately $30 million in stolen funds — ranking it among the largest DeFi exploits of that era. The protocol attempted a v2 rebuild with re-audited contracts but has since fallen to near-zero TVL and market cap, with no meaningful development activity recorded after 2024.","sections":[{"content":"On May 2, 2021 at approximately 04:38 UTC, an attacker drained approximately $30 million from Spartan Protocol's liquidity pools on BSC. The root cause was a critical flaw in the calcLiquidityShare() function inside the removeLiquidity() smart contract logic. The function queried live (manipulable) pool balances rather than the protocol's cached baseAmountPooled and tokenAmountPooled reserve values. This allowed the attacker to artificially inflate the apparent pool balance immediately before burning liquidity tokens, resulting in disproportionately large withdrawals.\n\nThe attack was executed using a 100,000 WBNB flash loan borrowed from PancakeSwap. The attacker performed repeated WBNB-to-SPARTA swaps across multiple transactions — using smaller batch sizes to circumvent slippage protections — then transferred assets directly into the pool contract to inflate balances before burning LP tokens. This cycle was repeated approximately 20 times across five transactions, draining roughly 90% of pool liquidity. Stolen assets included approximately 2,643,882 SPARTA and 21,555 WBNB. The attacker subsequently routed proceeds through 1inch (swapping to BTCB and BETH), then through Nerve Finance into Anyswap to bridge funds out of BSC. The attacker's primary address on BSC was 0x3b6e77722e2bbe97c1cfa337b42c0939aeb83671.\n\nSecurity firm PeckShield and Amber Group published independent post-mortems confirming the vulnerability. Notably, CertiK had audited the protocol's v1 smart contracts in September–October 2020 and found no critical issues, raising concerns about the adequacy of pre-launch audits. The protocol's native SPARTA token fell more than 30–70% within hours of the exploit becoming public.","heading":"The May 2021 Flash Loan Exploit","sources":[{"url":"https://peckshield.medium.com/the-spartan-incident-root-cause-analysis-a0324cb4b42a","name":"peckshield.medium.com","type":"other","credibility":3},{"url":"https://medium.com/amber-group/exploiting-spartan-protocols-lp-share-calculation-flaws-391437855e74","name":"medium.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-spartan-protocol-hack-may-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2021/05/02/binance-smart-chains-spartan-protocol-loses-30m-in-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/spartan-protocol-exploit-results-in-loss-of-30m","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://bscscan.com/address/0x3b6e77722e2bbe97c1cfa337b42c0939aeb83671","name":"bscscan.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Spartan Protocol v1 was audited by CertiK in September–October 2020, prior to launch. CertiK's audit reportedly found no critical vulnerabilities — only minor issues and informational findings. Despite this clearance, the protocol suffered a $30 million exploit in May 2021 that stemmed from a flaw in core contract logic. This outcome illustrates a documented limitation of point-in-time smart contract audits: the audited code passed review, but the vulnerability in liquidity-share calculation was not caught.\n\nThe protocol's own post-mortem acknowledged that 'The Spartan Contracts were fully audited by CertiK prior to launch, along with the usual ongoing code reviews, so this is an unfortunate reminder that there are no 100% safeguards.' Following the exploit, the team commissioned a more extensive Code4rena (CodeArena) competitive audit of the v2 contract suite, which took place in January 2022 and was partially funded by a Binance BUIDL grant.","heading":"Audit Failure and Pre-Exploit Security Posture","sources":[{"url":"https://github.com/spartan-protocol/resources/blob/master/certik-audit.pdf","name":"github.com","type":"other","credibility":3},{"url":"https://www.certik.com/projects/spartanprotocol","name":"certik.com","type":"other","credibility":3},{"url":"https://spartanprotocol.medium.com/today-spartan-protocol-was-subject-to-an-exploit-targeting-the-liquidity-pools-8589b2069cef","name":"spartanprotocol.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Spartan Protocol was conceived and built by a pseudo-anonymous group of developers who publicly stated they chose anonymity to protect the project and promote decentralization, citing Bitcoin and THORChain as precedents. The project launched with no named founders, no official team, and no treasury. All initial SPARTA tokens were distributed through a Proof-of-Burn mechanism requiring users to burn existing BEP-20 tokens, with no private sale, no team allocation, and no airdrop.\n\nWhile community-driven anonymity is not inherently fraudulent, it means there is no accountable party for the $30 million hack — no named team members were held responsible, and no legal recourse was pursued against any individual. The decentralized structure also meant post-hack recovery efforts were community-organized rather than managed by a known legal entity. This governance model, combined with the scale of losses, elevates the risk profile for prospective users.","heading":"Anonymous Team and Governance Structure","sources":[{"url":"https://medium.com/spartanprotocol/announcing-the-spartan-protocol-e15af93a8a8f","name":"medium.com","type":"other","credibility":3},{"url":"https://blog.spartanprotocol.org/announcing-the-spartan-protocol/","name":"blog.spartanprotocol.org","type":"other","credibility":3},{"url":"https://medium.com/spartanprotocol/spartan-protocol-faqs-339c6ee6bf0","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Spartan Protocol's anonymous team published a recovery roadmap outlining four steps: understand the bug, attempt to recover remaining funds for affected liquidity providers, work with Binance on stolen fund recovery, and resume development toward v2. An allocation of unissued SPARTA tokens — drawn from the remaining ~35 million of the original 100 million 'Burn' distribution — was designated for affected LP holders.\n\nA v2 contract suite was eventually developed and audited via Code4rena in January 2022. However, no stolen funds were publicly confirmed as recovered from the attacker. The collaboration with Binance on fund recovery did not result in any reported restitution. The protocol's GitHub repositories show last commit activity in March 2024 for spartan-contracts and September 2023 for spartan-docs, indicating a significant slowdown in development. By 2025, CoinLore reported no price data received since April 19, 2025, suggesting potential delisting or abandonment.","heading":"Post-Hack Recovery Attempts and V2 Rebuild","sources":[{"url":"https://spartanprotocol.medium.com/rebuilding-spartan-protocol-25a2901e4637","name":"spartanprotocol.medium.com","type":"other","credibility":3},{"url":"https://blog.spartanprotocol.org/rebuilding-spartan-protocol/","name":"blog.spartanprotocol.org","type":"other","credibility":3},{"url":"https://spartanprotocol.medium.com/spartan-protocol-road-to-v2-cont-a1f7b431b4e","name":"spartanprotocol.medium.com","type":"other","credibility":3},{"url":"https://github.com/spartan-protocol","name":"github.com","type":"other","credibility":3},{"url":"https://x.com/spartanprotocol/status/1388654212024705024","name":"x.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The SPARTA token reached an all-time high of approximately $2.47 before the May 2021 exploit. Following the hack, it fell more than 30–70% within hours. Over the following years, the token experienced further sustained decline: from approximately $0.31 on January 1, 2022, to $0.0072 by January 1, 2023 — a drop of over 97% from its peak. As of mid-2025, CoinMarketCap listed the SPARTA market cap at approximately $13,000, with the token trading at approximately $0.00018. The circulating supply stands at roughly 74.9 million SPARTA.\n\nThe token's near-total collapse reflects both the lasting damage of the $30 million exploit on investor confidence and the broader post-2021 crypto market downturn. The protocol's TVL has fallen to negligible levels, and major exchange listings have been lost.","heading":"Token Price Collapse and Market Status","sources":[{"url":"https://coinmarketcap.com/currencies/spartan-protocol/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/spartan-protocol","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coincodex.com/crypto/spartan-protocol/","name":"coincodex.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Spartan Protocol hack occurred during a period of concentrated exploit activity on Binance Smart Chain in spring 2021. BSC-based hackers extracted over $167 million using flash loans and exploits in May 2021 alone. The Spartan hack followed Uranium Finance's $57.2 million exploit (April 28, 2021) by only four days, and was preceded by Meerkat Finance ($32 million) earlier that same month. At the time, Spartan ranked as the sixth-largest monetary DeFi exploit in history.\n\nThe clustering of BSC exploits during this period drew significant criticism of BSC's security ecosystem, the speed at which projects launched without sufficient security review, and the reliance on audit firms that did not catch critical vulnerabilities. Spartan Protocol was often cited alongside these other incidents as an example of systemic risk in the BSC DeFi landscape.","heading":"Broader BSC Exploit Context","sources":[{"url":"https://protos.com/bsc-binance-smart-chainflash-loan-attacks-crypto-may/","name":"protos.com","type":"other","credibility":3},{"url":"https://beincrypto.com/spartan-defi-suffers-30m-loss-bsc-flash-loan-attack/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.benzinga.com/markets/cryptocurrency/21/05/20909436/another-day-another-defi-hack-spartan-protocol-exploited-for-over-30m","name":"benzinga.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09-18","event":"CertiK begins audit of Spartan Protocol v1 smart contracts; audit revised October 5, 2020. No critical vulnerabilities reported.","source":""},{"date":"2020-10-05","event":"CertiK audit finalized with no critical findings. Protocol proceeds toward launch on Binance Smart Chain.","source":""},{"date":"2021-02","event":"Spartan Protocol publicly operational on BSC with SPARTA token distributed via Proof-of-Burn mechanism.","source":"","date_original":"2021-02-01"},{"date":"2021-05-02","event":"Flash loan exploit drains approximately $30 million from Spartan Protocol liquidity pools. Attacker uses 100,000 WBNB flash loan from PancakeSwap to exploit calcLiquidityShare() vulnerability. Attacker address: 0x3b6e77722e2bbe97c1cfa337b42c0939aeb83671.","source":""},{"date":"2021-05-02","event":"PeckShield and Amber Group publish independent root cause analyses. SPARTA token falls 30–70% within hours of news.","source":""},{"date":"2021-05-02","event":"Spartan Protocol team publishes post-mortem and recovery roadmap via Twitter and Medium, announcing plans to work with Binance on fund recovery and resume v2 development.","source":""},{"date":"2021-05-03","event":"Over $100,000 in additional user funds reported still at risk across multiple BSC pairs (WBNB, BUSD, CREAM, ETH, BURGER, XRP, DOT, LINK, RAVEN).","source":""},{"date":"2022","event":"Code4rena competitive audit of Spartan Protocol v2 contract suite completed, funded in part by Binance BUIDL grant.","source":"","date_original":"2022-01-01"},{"date":"2023-09-25","event":"Last recorded update to spartan-docs GitHub repository, signaling slowdown in documentation maintenance.","source":""},{"date":"2024-03-07","event":"Last recorded commit to spartan-contracts GitHub repository, indicating near-cessation of active development.","source":""},{"date":"2025-04-19","event":"CoinLore reports no price data received for SPARTA after this date, suggesting possible delisting or abandonment. Market cap falls to approximately $13,000.","source":""}],"sources_used":[{"url":"https://peckshield.medium.com/the-spartan-incident-root-cause-analysis-a0324cb4b42a","name":"peckshield.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250910053912/https://peckshield.medium.com/the-spartan-incident-root-cause-analysis-a0324cb4b42a","credibility":3,"archive_timestamp":"2025-09-10T05:39:12+00:00"},{"url":"https://medium.com/amber-group/exploiting-spartan-protocols-lp-share-calculation-flaws-391437855e74","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/explained-the-spartan-protocol-hack-may-2021","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260414174708/https://www.halborn.com/blog/post/explained-the-spartan-protocol-hack-may-2021","credibility":3,"archive_timestamp":"2026-04-14T17:47:08+00:00"},{"url":"https://www.coindesk.com/markets/2021/05/02/binance-smart-chains-spartan-protocol-loses-30m-in-exploit","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260725154129/https://www.coindesk.com/markets/2021/05/02/binance-smart-chains-spartan-protocol-loses-30m-in-exploit","credibility":3,"archive_timestamp":"2026-07-25T15:41:29+00:00"},{"url":"https://cointelegraph.com/news/spartan-protocol-exploit-results-in-loss-of-30m","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260726001513/https://cointelegraph.com/news/spartan-protocol-exploit-results-in-loss-of-30m","credibility":3,"archive_timestamp":"2026-07-26T00:15:13+00:00"},{"url":"https://bscscan.com/address/0x3b6e77722e2bbe97c1cfa337b42c0939aeb83671","name":"bscscan.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://github.com/spartan-protocol/resources/blob/master/certik-audit.pdf","name":"github.com","type":"other","archive_url":"http://web.archive.org/web/20260528021023/https://github.com/spartan-protocol/resources/blob/master/certik-audit.pdf","credibility":3,"archive_timestamp":"2026-05-28T02:10:23+00:00"},{"url":"https://www.certik.com/projects/spartanprotocol","name":"certik.com","type":"other","archive_url":"https://web.archive.org/web/20260830132036/https://skynet.certik.com/projects/spartanprotocol","credibility":3,"archive_timestamp":"2026-08-30T13:20:36+00:00"},{"url":"https://spartanprotocol.medium.com/today-spartan-protocol-was-subject-to-an-exploit-targeting-the-liquidity-pools-8589b2069cef","name":"spartanprotocol.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260725145555/https://spartanprotocol.medium.com/today-spartan-protocol-was-subject-to-an-exploit-targeting-the-liquidity-pools-8589b2069cef","credibility":3,"archive_timestamp":"2026-07-25T14:55:55+00:00"},{"url":"https://medium.com/spartanprotocol/announcing-the-spartan-protocol-e15af93a8a8f","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.spartanprotocol.org/announcing-the-spartan-protocol/","name":"blog.spartanprotocol.org","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/spartanprotocol/spartan-protocol-faqs-339c6ee6bf0","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://spartanprotocol.medium.com/rebuilding-spartan-protocol-25a2901e4637","name":"spartanprotocol.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260725145532/https://spartanprotocol.medium.com/rebuilding-spartan-protocol-25a2901e4637","credibility":3,"archive_timestamp":"2026-07-25T14:55:32+00:00"},{"url":"https://blog.spartanprotocol.org/rebuilding-spartan-protocol/","name":"blog.spartanprotocol.org","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://spartanprotocol.medium.com/spartan-protocol-road-to-v2-cont-a1f7b431b4e","name":"spartanprotocol.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://github.com/spartan-protocol","name":"github.com","type":"other","archive_url":"http://web.archive.org/web/20260815213730/https://github.com/spartan-protocol","credibility":3,"archive_timestamp":"2026-08-15T21:37:30+00:00"},{"url":"https://x.com/spartanprotocol/status/1388654212024705024","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coinmarketcap.com/currencies/spartan-protocol/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260725152540/https://coinmarketcap.com/currencies/spartan-protocol/","credibility":3,"archive_timestamp":"2026-07-25T15:25:40+00:00"},{"url":"https://www.coingecko.com/en/coins/spartan-protocol","name":"coingecko.com","type":"other","archive_url":"http://web.archive.org/web/20260725211533/https://www.coingecko.com/en/coins/spartan-protocol","credibility":3,"archive_timestamp":"2026-07-25T21:15:33+00:00"},{"url":"https://coincodex.com/crypto/spartan-protocol/","name":"coincodex.com","type":"other","archive_url":"http://web.archive.org/web/20260414060609/https://coincodex.com/crypto/spartan-protocol/","credibility":3,"archive_timestamp":"2026-04-14T06:06:09+00:00"},{"url":"https://protos.com/bsc-binance-smart-chainflash-loan-attacks-crypto-may/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260511084742/https://protos.com/bsc-binance-smart-chainflash-loan-attacks-crypto-may/","credibility":3,"archive_timestamp":"2026-05-11T08:47:42+00:00"},{"url":"https://beincrypto.com/spartan-defi-suffers-30m-loss-bsc-flash-loan-attack/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.benzinga.com/markets/cryptocurrency/21/05/20909436/another-day-another-defi-hack-spartan-protocol-exploited-for-over-30m","name":"benzinga.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:58.039753+00:00","updated_at":"2026-09-01T04:16:57.940632+00:00"}}