{"investigation":{"slug":"surgebnb","entity_name":"SurgeBNB","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"SurgeBNB was a BEP-20 yield token on Binance Smart Chain operated by the XSurge DeFi project. On August 16–17, 2021, an attacker exploited a reentrancy vulnerability in the contract's sell() function via a flash loan, draining approximately 13,111 BNB (~$5 million USD) from the protocol. The project had publicly claimed to be 'rug-proof' prior to the exploit; post-hack, the team launched a 'SurgeFund' compensation scheme, though the extent and completion of repayment to victims remains unclear.","sections":[{"content":"On August 16–17, 2021, SurgeBNB suffered a critical security exploit classified as a reentrancy-based flash loan attack. The attacker borrowed 10,000 BNB through a flash loan, used the funds to purchase SURGE tokens, and then exploited a flaw in the contract's sell() function. The vulnerability allowed the attacker to re-enter the contract before the totalSupply state variable was updated, enabling repeated buy cycles at artificially depressed prices. The total profit extracted by the attacker exceeded 13,111 BNB, valued at approximately $5 million USD at the time. The attacker's contract address has been identified as 0x1514AAA4dCF56c4Aa90da6a4ed19118E6800dc46, and a second wallet address of 0x59c686272e6f11dC8701A162F938fb085D940ad3 was also associated with the attack. Blockchain security firms BEOSIN and Knownsec independently analyzed and published technical post-mortems confirming the reentrancy vector. SurgeBNB was the only token in the XSurge product suite found to be vulnerable to this particular exploit.","heading":"Exploit Overview","sources":[{"url":"https://beosin.medium.com/a-sweet-blow-fb0a5e08657d","name":"beosin.medium.com","type":"other","credibility":3},{"url":"https://medium.com/@Knownsec_Blockchain_Lab/knowsec-blockchain-lab-xsurge-flash-loan-attack-analysis-b57b75ce6a30","name":"medium.com","type":"other","credibility":3},{"url":"https://binancechain.news/xsurge-faces-5000000-exploit-despite-promises-of-security/2021/08/16/","name":"binancechain.news","type":"other","credibility":3}],"severity":"critical"},{"content":"Prior to the August 2021 exploit, XSurge and its associated developer known publicly as 'DefiMark' (also previously known as 'SafemoonMark') made repeated public claims that the protocol was immune to rug pulls. The project's official webpage stated: 'With ownership fully renounced, no liquidity, and no need for DApps, there is no possibility of a rug pull or whale dominance.' Community-published materials echoed these claims, with one post stating 'There is absolutely no risk of a rug pull.' DefiMark, credited as the lead developer, had previously worked on the SafeMoon project and made security assurances via social media. Following the exploit, investors expressed frustration at the broken promises, with one documented community member stating 'I'm $1500 down: normally I would say I knew my risks but you guys said rug proof.' These claims did not constitute a rug pull in the technical sense, as the exploit was an external attack rather than a developer-initiated drain; however, the public assurances were alleged by critics to have been misleading regarding the true security posture of the contract.","heading":"Pre-Exploit Security Claims","sources":[{"url":"https://binancechain.news/xsurge-faces-5000000-exploit-despite-promises-of-security/2021/08/16/","name":"binancechain.news","type":"other","credibility":3},{"url":"https://x.com/xsurgedefi/status/1427347715915190274","name":"x.com","type":"other","credibility":3}],"severity":"high"},{"content":"Security analysis by BEOSIN and Knownsec identified the root cause as a classic checks-effects-interactions violation in the sell() function. The function transferred BNB to the caller before updating the contract's totalSupply, creating a window in which a malicious fallback function could re-invoke the purchase logic. Notably, the contract contained a nonReentrant modifier, but analysts concluded this guard was insufficient to prevent the 'pseudo-reentrancy' exploited in this attack, because the price calculation depended on totalSupply which had not yet been updated. Security experts recommended that projects use state-change-before-transfer patterns and restrict low-level 'call' operations. The XSurge team publicly warned about an unpatched vulnerability in the SurgeBNB contract on August 16, 2021, urging users to migrate funds; the exploit followed almost immediately after this disclosure, suggesting the attacker may have been monitoring communications or was already aware of the flaw.","heading":"Technical Vulnerability Analysis","sources":[{"url":"https://beosin.medium.com/a-sweet-blow-fb0a5e08657d","name":"beosin.medium.com","type":"other","credibility":3},{"url":"https://medium.com/@Knownsec_Blockchain_Lab/knowsec-blockchain-lab-xsurge-flash-loan-attack-analysis-b57b75ce6a30","name":"medium.com","type":"other","credibility":3}],"severity":"critical"},{"content":"The XSurge protocol was developed by a pseudonymous developer publicly known as 'DefiMark,' who previously operated under the handle 'SafemoonMark' and was associated with the SafeMoon project on BSC. No verified legal identity for this developer has been confirmed in available public records. After the hack, DefiMark hosted a public Discord AMA livestream to address the incident. The team's anonymity, combined with prior affiliation with the widely criticized SafeMoon project, has been cited by community observers as a concern regarding accountability. No regulatory filings, corporate registrations, or independent audits of the SurgeBNB contract have been identified in available public records.","heading":"Team Identity and Transparency","sources":[{"url":"https://rumble.com/v100a06-defimark-discord-ama-livestream-addressing-the-surgebnb-hack.html","name":"rumble.com","type":"other","credibility":3},{"url":"https://binancechain.news/xsurge-faces-5000000-exploit-despite-promises-of-security/2021/08/16/","name":"binancechain.news","type":"other","credibility":3}],"severity":"high"},{"content":"Following the exploit, the XSurge team launched a compensation mechanism called SurgeFund, described as a charitable donation fund intended to reimburse affected users. Under the stated terms, each victim would receive the dollar value of their loss at the time of the hack plus 1%, payable in either BUSD or XUSD stablecoin at the claimant's discretion. A 'snowball method' was described for prioritizing smaller victims, with 83% of victims reportedly having lost less than 1 BNB. A SurgeFund Repayment (SFR) token was also issued as part of the mechanism. The SurgeFund reached at least version 3 (SurgeFund V3). The completeness and final outcome of victim repayment has not been independently verified in available public sources; it is unclear whether all victims were made whole.","heading":"Victim Compensation Effort","sources":[{"url":"https://xsurge.net/surgefund","name":"xsurge.net","type":"other","credibility":3},{"url":"https://desk.lsr.finance/asset/sfr-surgefund-repayment/","name":"desk.lsr.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"According to AVOID.NET's internal context, the on-chain investigator ZachXBT flagged SurgeBNB as a notable entity of concern. ZachXBT is a widely recognized pseudonymous blockchain investigator known for exposing scams, rug pulls, and protocol exploits across the crypto ecosystem, and whose findings are regularly cited by Tier 1 and Tier 2 media outlets. The specific nature of ZachXBT's flag on SurgeBNB has not been independently located in a publicly archived post at the time of this investigation; the flag context provided is that it relates to the August 2021 exploit and associated events. This section will be updated if a primary source is located.","heading":"ZachXBT Flag","sources":[{"url":"https://cointelegraph.com/news/zachxbt-rug-pull-unpaid-work","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"high"}],"timeline":[{"date":"2021-07-30","event":"Developer 'SafemoonMark' (DefiMark) publicly touts SurgeBNB as safe from rug pulls via Twitter.","source":""},{"date":"2021-08-16","event":"XSurge team publicly warns community of an unpatched vulnerability in the SurgeBNB contract and urges users to migrate funds immediately.","source":""},{"date":"2021-08-16","event":"SurgeBNB contract is exploited via a flash loan reentrancy attack; over 13,111 BNB (~$5 million USD) drained from the protocol.","source":""},{"date":"2021-08-17","event":"Official XSurge Twitter account (@XSURGEDEFI) confirms the hack and posts attacker wallet details.","source":""},{"date":"2021-08-17","event":"BEOSIN publishes full technical post-mortem identifying the reentrancy vulnerability in the sell() function.","source":""},{"date":"2021-08-17","event":"Knownsec Blockchain Lab publishes independent flash loan attack analysis corroborating BEOSIN findings.","source":""},{"date":"2021-08-17","event":"DefiMark hosts Discord AMA livestream to address community concerns about the SurgeBNB hack.","source":""},{"date":"2021-09","event":"XSurge launches SurgeFund compensation mechanism; SurgeFund Repayment (SFR) token issued to track victim claims.","source":"","date_original":"2021-09-01"}],"sources_used":[{"url":"https://beosin.medium.com/a-sweet-blow-fb0a5e08657d","name":"BEOSIN: XSURGE Flash Loan Attack Full Analysis","type":"research","archive_url":"http://web.archive.org/web/20250908022728/https://beosin.medium.com/a-sweet-blow-fb0a5e08657d","credibility":2,"archive_timestamp":"2025-09-08T02:27:28+00:00"},{"url":"https://medium.com/@Knownsec_Blockchain_Lab/knowsec-blockchain-lab-xsurge-flash-loan-attack-analysis-b57b75ce6a30","name":"Knownsec Blockchain Lab: XSURGE Flash Loan Attack Analysis","type":"research","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://binancechain.news/xsurge-faces-5000000-exploit-despite-promises-of-security/2021/08/16/","name":"Binance Chain News: XSurge Faces $5,000,000 Exploit Despite Promises of Security","type":"news_article","archive_url":"http://web.archive.org/web/20260117221350/https://binancechain.news/xsurge-faces-5000000-exploit-despite-promises-of-security/2021/08/16/","credibility":2,"archive_timestamp":"2026-01-17T22:13:50+00:00"},{"url":"https://x.com/xsurgedefi/status/1427347715915190274","name":"XSURGE Official Twitter — Hack Announcement","type":"social_media","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.trendsmap.com/twitter/tweet/1427359459102404609","name":"XSURGE Trendsmap — Hack Address Tweet","type":"social_media","archive_url":null,"credibility":3,"archive_error":"error:invalid-host-resolution","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://xsurge.net/surgefund","name":"XSurge SurgeFund Official Page","type":"official","archive_url":null,"credibility":2,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://rumble.com/v100a06-defimark-discord-ama-livestream-addressing-the-surgebnb-hack.html","name":"DefiMark Discord AMA Livestream — Addressing the SurgeBNB Hack","type":"other","archive_url":"https://web.archive.org/web/20260724180533/https://rumble.com/v100a06-defimark-discord-ama-livestream-addressing-the-surgebnb-hack.html","credibility":3,"archive_timestamp":"2026-07-24T18:05:33+00:00"},{"url":"https://desk.lsr.finance/asset/sfr-surgefund-repayment/","name":"SurgeFund Repayment (SFR) Token Info — lsr.finance","type":"on_chain","archive_url":"https://web.archive.org/web/20260724175531/https://desk.lsr.finance/asset/sfr-surgefund-repayment/","credibility":2,"archive_timestamp":"2026-07-24T17:55:31+00:00"},{"url":"https://www.youtube.com/watch?v=UGmbjjGoh8M","name":"YouTube: SurgeBnb Has Been Hacked — Over $4 Million Dollars Worth of BNB Stolen","type":"other","archive_url":"https://web.archive.org/web/20260724215238/https://www.youtube.com/watch?v=UGmbjjGoh8M","credibility":3,"archive_timestamp":"2026-07-24T21:52:38+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:54.902483+00:00","updated_at":"2026-08-29T01:36:07.295+00:00"}}