Meteora DAMM V2 Hack
What happened
On January 17, 2026, Meteora lost approximately $1.5M in USDC through a fake OTC escrow deal on Solana.
The OTC workflow relied on off-chain identity, communication, and escrow-address verification without an independently verified atomic escrow or multisignature release condition. That trust gap allowed a forged counterparty and wallet to receive the payment.
How it happened
Scammers impersonated both sides of a token buyback conversation and directed Meteora to send USDC to a fraudulent escrow wallet. The legitimate seller did not receive the funds; the loss came from the off-chain coordination and payment process, not a DAMM V2 contract exploit.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.