MAP Protocol Hack
What happened
On May 20, 2026, an attacker exploited MAP Protocol's Butter Bridge V3.1 OmniServiceProxy, causing unauthorized MAPO minting on Ethereum and BSC. Approximately $110,000 in value was realized by dumping part of the minted supply; MAP Protocol paused the bridge and announced a migration and user-protection plan.
Butter Bridge V3.1 verified retry messages using a packed hash over dynamic fields; a CREATE2-deployed contract and rearranged message fields produced a collision with an already accepted message, allowing the retry path to mint MAPO without a matching source transfer.
How it happened
The attacker used a legitimate bridge message and a crafted retry path to mint one quadrillion MAPO on Ethereum without a corresponding source-chain lock or burn, then sold part of the minted supply into liquidity pools.
Protocol details
Evidence
- report MAP Protocol: May updates and Butter Bridge incident response medium.com
- analysis DeFiLlama defillama.com
- analysis OAK: MAP Protocol Butter Bridge abi.encodePacked collision onchainattack.org
- analysis CryptoAdventure: MAP Protocol infinite-mint bridge exploit cryptoadventure.com
- analysis Our Crypto Talk: Butter Bridge exploit trace ourcryptotalk.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.