Meta Pool Hack
What happened
Meta Pool's mpETH staking contract allowed tokens to be minted without supplying their ETH backing. The attacker bypassed an internal liquidity-swap branch and used the inherited ERC-4626 mint function to create unbacked mpETH, then converted tokens through available liquidity.
Meta Pool customized _deposit while leaving the inherited ERC-4626 mint entry point exposed. The resulting path lacked the asset-transfer validation needed before issuing shares. Emptying the internal pool avoided a swap branch that would otherwise fail.
How it happened
- The attacker emptied the internal pool's available mpETH so the staking contract would skip its swap branch.
- The inherited mint function reached the customized _deposit implementation without requiring an ETH payment.
- The contract issued mpETH despite receiving no backing assets.
- The attacker exchanged some of these tokens for ETH through liquidity pools.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.