Meteora DAMM V2 Hack

Reported loss $1.5M
Solana
Fake OTC Escrow

What happened

On January 17, 2026, Meteora lost approximately $1.5M in USDC through a fake OTC escrow deal on Solana.

Technical root cause

The OTC workflow relied on off-chain identity, communication, and escrow-address verification without an independently verified atomic escrow or multisignature release condition. That trust gap allowed a forged counterparty and wallet to receive the payment.

How it happened

Scammers impersonated both sides of a token buyback conversation and directed Meteora to send USDC to a fraudulent escrow wallet. The legitimate seller did not receive the funds; the loss came from the off-chain coordination and payment process, not a DAMM V2 contract exploit.

Protocol details

Classification Social Engineering
Protocol Type DEX
Implementation language Rust
Protocol links Website @MeteoraAG

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.