MintPal Hack
What happened
On July 13, 2014, an attacker exploited a vulnerability in MintPal's withdrawal system to authorize withdrawals from the exchange's VeriCoin hot wallet. About 8 million VRC, reported as roughly 30% of the supply and about $2 million, were taken. VeriCoin developers hard-forked the network to orphan the theft transactions after MintPal's custody failure; the incident was not a compromise of the VeriCoin protocol.
How it happened
- The attacker exploited MintPal's withdrawal system to bypass its internal controls and initialize a VeriCoin wallet withdrawal.
- Because MintPal had left a large portion of its VRC balance in the online hot wallet, the attacker could withdraw about 8 million VRC.
- MintPal contacted the VeriCoin team, which chose to fork the blockchain to a point before the theft.
- A first rollback did not hold because older clients continued broadcasting the transaction.
- A second fork orphaned the theft blocks and moved the 8 million VRC to a replacement wallet; MintPal also said it would cover rollback-related losses.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.