MintPal Hack

Reported loss $2.0M
Bitcoin
Access Control

What happened

On July 13, 2014, an attacker exploited a vulnerability in MintPal's withdrawal system to authorize withdrawals from the exchange's VeriCoin hot wallet. About 8 million VRC, reported as roughly 30% of the supply and about $2 million, were taken. VeriCoin developers hard-forked the network to orphan the theft transactions after MintPal's custody failure; the incident was not a compromise of the VeriCoin protocol.

How it happened

  1. The attacker exploited MintPal's withdrawal system to bypass its internal controls and initialize a VeriCoin wallet withdrawal.
  2. Because MintPal had left a large portion of its VRC balance in the online hot wallet, the attacker could withdraw about 8 million VRC.
  3. MintPal contacted the VeriCoin team, which chose to fork the blockchain to a point before the theft.
  4. A first rollback did not hold because older clients continued broadcasting the transaction.
  5. A second fork orphaned the theft blocks and moved the 8 million VRC to a replacement wallet; MintPal also said it would cover rollback-related losses.

Protocol details

Classification CeFi / Access Control
Protocol Type Exploit/Access control

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.