Meter.io Hack

TOTAL LOST $4.4M
Medium Other

What happened

Meter Passport's wrapped-native-token deposit handler allowed direct calls with arbitrary calldata amounts because it did not verify the native value supplied. The attacker forged bridge deposits, minted unbacked BNB and WETH representations, and drained bridge reserves.

Case & protocol details

Classification Other
Protocol Type Exploit/Other
Affected asset / contract MTRG
Official Website meter.io/
Protocol Twitter/X @Meter_IO

Attack Timeline

Meter modified ChainBridge's ERC20 handler to support automatic wrapping and unwrapping of ETH and BNB. That design assumed wrapped-native deposits had already transferred value, so the handler could skip normal token locking or burning. Although the intended depositEth route checked the amount, the publicly callable underlying deposit route did not ensure msg.value matched the amount encoded in calldata.

The attacker called that route directly with inflated values, creating unbacked bridge assets, then redeemed or sold them across BSC, Ethereum, Moonriver, and Meter.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.