Meta Pool Hack

Reported loss $130K
Ethereum
Infinite Mint

What happened

Meta Pool's mpETH staking contract allowed tokens to be minted without supplying their ETH backing. The attacker bypassed an internal liquidity-swap branch and used the inherited ERC-4626 mint function to create unbacked mpETH, then converted tokens through available liquidity.

Technical root cause

Meta Pool customized _deposit while leaving the inherited ERC-4626 mint entry point exposed. The resulting path lacked the asset-transfer validation needed before issuing shares. Emptying the internal pool avoided a swap branch that would otherwise fail.

How it happened

  1. The attacker emptied the internal pool's available mpETH so the staking contract would skip its swap branch.
  2. The inherited mint function reached the customized _deposit implementation without requiring an ETH payment.
  3. The contract issued mpETH despite receiving no backing assets.
  4. The attacker exchanged some of these tokens for ETH through liquidity pools.

Protocol details

Classification Token & Share Accounting / Other
Protocol Type Exploit/Other
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.