MetaPoint Hack

REPORTED LOSS $820K
Low Access Control bsc

What happened

MetaPoint was exploited due to a vulnerability in the deposit function, resulting in the loss of $700K worth of USDT/POT pool tokens.

MetaPoint is a metaverse running on the Binance Smart Chain. The project was hacked through a vulnerability found within their deposit function. When a user used the deposit function, it created a new contract and deposited tokens into that contract.

The issue arose because this newly created contract had an "approve" function that gave unrestricted access to $META tokens without any restrictions or limitations. An attacker took advantage of this by deploying a malicious smart contract with unverified source code, and draining mass amounts of funds from users who had deposited $POT tokens onto their platform. The exploiter was able to steal 2,518 $BNB which is worth 803,242 $USD at current market rates.

All the stolen money transferred through TornadoCash.

Attacker address:

https://bscscan.com/address/0x0d1969a3…ba8373

Malicious Contract:

https://bscscan.com/address/0xc6e451c8…3c5d5c

Malicious Transaction Example:

https://bscscan.com/tx/0x0ed5cc9a…59c4c4

Case & protocol details

Classification Gaming / Metaverse / Access Control
Protocol Type Exploit/Access control
Affected asset / contract POT
Implementation language Solidity
Official Website metapoint.plus/
Protocol Twitter/X @MetaPoint1024

Evidence & learning

Sources and on-chain records

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.