Meter.io Hack
What happened
Meter Passport's wrapped-native-token deposit handler allowed direct calls with arbitrary calldata amounts because it did not verify the native value supplied. The attacker forged bridge deposits, minted unbacked BNB and WETH representations, and drained bridge reserves.
Case & protocol details
Attack Timeline
Meter modified ChainBridge's ERC20 handler to support automatic wrapping and unwrapping of ETH and BNB. That design assumed wrapped-native deposits had already transferred value, so the handler could skip normal token locking or burning. Although the intended depositEth route checked the amount, the publicly callable underlying deposit route did not ensure msg.value matched the amount encoded in calldata.
The attacker called that route directly with inflated values, creating unbacked bridge assets, then redeemed or sold them across BSC, Ethereum, Moonriver, and Meter.
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
- report Post-mortem rekt.news
- report Report twitter.com
- report Post-mortem medium.com
- analysis Halborn: The Meter.io Hack, February 2022 halborn.com
- analysis CoinDesk: $4.4M stolen in Meter hack coindesk.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.