Minterest Hack
What happened
Minterest's Mantle market lost about $1.4 million after an unaudited mUSDY extension allowed flash-loan-assisted reentrancy and exchange-rate manipulation. The incident occurred July 14, 2024; the July 15 record date reflects public reporting. Ethereum and Taiko deployments were unaffected.
A Mantle-specific, unaudited mUSDY market extension allowed reentrancy during a distorted exchange-rate state. The reentrant lending path minted more mTokens than intended, while later withdrawals applied the normal rate.
Case & protocol details
Attack Timeline
A flash loan lowered market cash and altered the exchange rate. The attacker's fallback converted borrowed USDY to mUSD and re-entered through lendRUSDY while the distorted rate was used, minting excess mTokens. Withdrawals then used the correct rate, leaving excess mUSDY tokens.
Repeating the cycle built excess mTokens and enabled borrowing and draining WETH and mETH. Minterest paused Mantle operations, patched the mUSDY and exchange-rate paths, and offered a recovery bounty, but no attacker-fund recovery is confirmed.
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 available- Code Minterest Reentrancy
Sources and on-chain records
- report Report x.com
- report Minterest Security Incident Post-Mortem minterest.com
- transaction Transaction explorer.mantle.xyz
- analysis Website reference x.com
- analysis Minterest Hack Analysis halborn.com
- analysis Minterest CEO Letter minterest.com
- analysis Minterest Reopening Update minterest.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.