Minterest Hack

TOTAL LOST $1.4M
Medium Flash Loan Attacks Mantle

What happened

Minterest's Mantle market lost about $1.4 million after an unaudited mUSDY extension allowed flash-loan-assisted reentrancy and exchange-rate manipulation. The incident occurred July 14, 2024; the July 15 record date reflects public reporting. Ethereum and Taiko deployments were unaffected.

Technical Root Cause

A Mantle-specific, unaudited mUSDY market extension allowed reentrancy during a distorted exchange-rate state. The reentrant lending path minted more mTokens than intended, while later withdrawals applied the normal rate.

Case & protocol details

Classification Reentrancy / lending protocol logic and exchange-rate manipulation
Protocol Type Lending
Smart Contract Language Solidity
Official Website minterest.com/
Protocol Twitter/X @Minterest

Attack Timeline

A flash loan lowered market cash and altered the exchange rate. The attacker's fallback converted borrowed USDY to mUSD and re-entered through lendRUSDY while the distorted rate was used, minting excess mTokens. Withdrawals then used the correct rate, leaving excess mUSDY tokens.

Repeating the cycle built excess mTokens and enabled borrowing and draining WETH and mETH. Minterest paused Mantle operations, patched the mUSDY and exchange-rate paths, and offered a recovery bounty, but no attacker-fund recovery is confirmed.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.