Worked example · 2021-03
Meerkat Finance deployer-drain exit scam — BSC — 2021-03-04
Summary
Meerkat Finance launched on Binance Smart Chain on 2021-03-03 as a yield-farming vault protocol. The protocol offered depositors the ability to stake BUSD and BNB into a vault that promised high APY returns generated by a proprietary yield-aggregation strategy. The vault contract was controlled by a single deployer address — the project's owner — which held the admin key with authority to call administrative functions on the vault.
Within 24 hours of launch, approximately $31M in user funds (13.96M BUSD + 73,635 BNB) had been deposited into the vault — an extraordinarily fast inflow driven by the BSC yield-farming wave of Q1 2021, during which protocols launching on BSC routinely attracted hundreds of millions of dollars in deposits within hours of going live.
On 2021-03-04, the Meerkat Telegram channel announced that the protocol had been "hacked" and that the vault's funds had been stolen. The announcement was quickly recognised as fraudulent by on-chain security analysts. The transaction record showed that the vault drain was executed by the deployer address itself: the admin wallet called the vault contract's administrative withdrawal function (or, in some analyses, directly transferred the vault's token balance via a pre-authorized ownership transfer), moving the entire deposited BUSD and BNB balance to a separate address controlled by the deployer — not to an address consistent with an external exploit pattern.
The Meerkat team's social channels were deleted within hours. The on-chain forensics — deployer-wallet funding patterns, wallet clustering, and the absence of any pre-drain contract interaction from an external attacker address that could not be traced back to the deployer — were independently verified by PeckShield, CertiK, SlowMist, and the on-chain-analytics community. The forensic consensus was that Meerkat was an exit scam from inception, not a protocol that was later exploited by an external actor.
Meerkat was one of the earliest and largest exit scams on BSC, establishing a pattern — anonymous team, extreme APY to attract deposits within 24-48 hours, single admin-key drain, "hacked" cover story, social-channel deletion — that was replicated by dozens of subsequent BSC yield-farm rug-pulls throughout 2021, including the Compounder Finance (December 2020), Big Daddy Ape Club (December 2021), and the broader BSC yield-farm rug-pull wave of Q1-Q2 2022.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2021-03-03 | Meerkat Finance launches vault on BSC; depositors rush in, ~$31M deposited within <24 hours | (standing T5.005 surface: single deployer admin-key control over vault) |
| 2021-03-04 ~09:00 | Deployer executes vault drain: admin-key-controlled function transfers all deposited BUSD + BNB to deployer-controlled exit address | T5.001 (hard LP drain), T5.005 (treasury-management exit) |
| 2021-03-04 ~09:30 | Meerkat Telegram announces "hack"; on-chain analysts immediately identify deployer-drain pattern, labelling exit scam | (community detection) |
| 2021-03-04 ~10:00 | Meerkat deletes Telegram, Twitter, website; no further communication from the team | (team exit) |
| 2021-03-04 to 2021-03-05 | On-chain analytics firms (PeckShield, CertiK, SlowMist) publish exit-scam confirmations; fund flow traced through BSC bridge-offs and intermediary wallets | (forensic analysis) |
Realised extraction
Approximately $31M: 13.96M BUSD + 73,635 BNB, entirely drained by the deployer address. Funds were bridged off BSC through multiple intermediary wallets and were not recovered as of the latest public on-chain tracing record.
T5.005 classification
Meerkat Finance is a canonical OAK-T5.005 (Treasury-Management Exit) worked example, specifically in the deployer-admin-key-drain sub-shape. The vault's admin key — held by the deployer address — granted privileged authority to transfer the vault's full token balance. The exit was executed by the entity with the highest level of trust in the protocol's governance architecture (the deployer), making it structurally distinct from an external-access-control exploit (T9.004) where an attacker gains unauthorized access to a function intended to be permissioned.
The T5.005 classification at v0.1 extends to any case where a protocol's treasury or vault is drained by a party with legitimate, privileged access authority — including deployer exits (Meerkat), CEO / founder misappropriation (FTX), and multisig-signer insider action (Cypher Protocol May 2024, the hoak insider-redemption case). The unifying pattern is that the drain is executed with the contract's own permission structure, not in violation of it.
T5.001 classification
The single-transaction vault drain — transferring the entire deposited balance (not a gradual trickle, not a series of smaller withdrawals) — matches the OAK-T5.001 (Hard LP Drain) pattern: a single, large outflow that extracts effectively the entire LP or vault balance in one action. The T5.001 classification is the extraction-velocity dimension; T5.005 is the authority dimension (who drained it). The two are complementary: a T5.005 exit can exhibit either a hard-drain (T5.001, single-transaction, as at Meerkat) or a slow-drain (T5.002, multi-transaction over time, as at QuadrigaCX or a prolonged operator-compromise).
Public references
- PeckShield, "Meerkat Finance — Deployer Drain Confirmation," Twitter (@PeckShieldAlert), March 4, 2021
- CertiK, "Meerkat Finance Exit Scam Analysis," March 4, 2021
- SlowMist, "Meerkat Finance Incident Report," March 4, 2021
- Rekt News, "Meerkat Finance — REKT," rekt.news, March 4, 2021
- BscScan — deployer address, drain transaction hash, and fund-flow analysis (March 4, 2021)