Cointime

Download App
iOS & Android

Meta Pool hit with $27M exploit, but attacker flees with only $132K

A hacker has managed to make off with only around $132,000 from their attack on the crypto protocol Meta Pool, which created $27 million worth of tokens they could have stolen. The attack was foiled by low liquidity and a pause on the exploited smart contract.

The attacker was able to mint 9,705 of the liquid staking protocol’s token mpETH worth nearly $27 million, but only managed to steal around 52.5 Ether (ETH), worth just over $132,000 from the liquidity swap pools, Meta Pool said in a blog post on Tuesday. 

It added that some of the affected pools had low liquidity and volumes, making it harder for the attack to be carried out, and its “early detection systems” helped its team quickly pause the affected contract, preventing “further unauthorized activity or additional losses.”

Hacker exploited “fast unstake” function

In an X post on Tuesday, Meta Pool co-founder Claudio Cossio said the hacker exploited a “fast unstake functionality,” allowing them to mint thousands of mpETH tokens.

Generally, after unstaking crypto, there is a waiting period before it becomes transferable; however, with fast unstaking, also known as flash unstaking, the waiting period is voided, provided specific conditions are met.

Blockchain security firm PeckShield posted to X that the staking contract had a “critical bug,” which allowed the hacker to mint mpETH for free, but the “low liquidity of mpETH limited the profit.”

  Source: Claudio Cossio

The Meta Pool team said that the attack “involved the unauthorized minting of tokens through the ERC4626 mint() function.”

Exploiter drains swap pools 

After minting the mpETH, the exploiter used most of it to drain the swap pools of 52.5 ETH, affecting several Ethereum mainnet and Optimism pools. 

The Meta Pool team said, however, that an affected Optimism pool had “low liquidity and volume.”

“It needs to be cleared that all the Ethereum staked is safe, delegated in the SSV Network operators which is validating blocks and accruing staking rewards on the Ethereum mainnet,” the Meta Pool team said.

A full post-mortem of the incident is expected in the next two days, along with a recovery plan, according to the Meta Pool team. In the meantime, the affected mpETH contract will remain paused while the investigation continues. 

Meta Pool promised to “reimburse the assets lost by this incident” and ensure users are “made whole.” 

Crypto protocols hit with exploits

Alex Protocol, a Bitcoin decentralized finance platform on the Stacks blockchain, suffered an exploit on June 6, with $8.3 million in losses after a bad actor used a flaw in the self-listing verification logic to drain liquidity from several asset pools. 

Meanwhile, Taiwan-based crypto exchange BitoPro confirmed on June 2 that a security breach led to the loss of more than $11.5 million in assets from its hot wallets on May 8.

Comments

All Comments

Recommended for you

  • Iranian Military Spokesman: Control Over Strait of Hormuz Restored Due to U.S. 'Breach of Promises'

    On April 18, Iranian media reported that an Iranian military spokesman stated that control over the Strait of Hormuz has been restored to its previous state due to the U.S. 'repeatedly breaching promises.' The strait is currently under strict management and control by the Iranian armed forces. (Xinhua News Agency)

  • BTC Falls Below $77,000

    Market data shows that BTC has fallen below $77,000, currently priced at $76,997.37, with a 24-hour increase of 2.68%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Iranian Civil Aviation Organization Announces Partial Reopening of Airspace

    According to Iranian media reports on the 18th, the Iranian Civil Aviation Organization announced the reopening of part of Iran's airspace and several airports. (Xinhua)

  • Bitcoin ETF Sees $663.9 Million Net Inflow, Ethereum ETF Sees $127.4 Million Net Inflow

    On April 18, according to Farside Investors, the U.S. Bitcoin spot ETF saw a net inflow of $663.9 million yesterday, with IBIT net inflow at $284 million, FBTC net inflow at $163.4 million, and ARKB net inflow at $117.9 million. The Ethereum ETF recorded a net inflow of $127.4 million yesterday, marking the seventh consecutive day of net inflows, with ETHA net inflow at $30.8 million and FETH net inflow at $84.1 million.

  • Trump Hints at 'Good News' on Iran Issue

    On April 18, U.S. President Donald Trump stated that there is some 'pretty good news' regarding the Iran issue, but he declined to provide further details. 'We heard some pretty good news about 20 minutes ago, and it seems that progress related to Iran in the Middle East is going very smoothly,' Trump told reporters aboard Air Force One. When asked what the so-called good news was, Trump replied, 'You will hear it. I think it is something that should happen. It is a matter of course. And I believe it will happen. We will see, but I think it will happen.' (Jinshi)

  • Trump Suggests War Will Resume if No Agreement with Iran is Reached

    On April 18, President Trump told reporters aboard Air Force One that if an agreement with Iran is not reached by Wednesday, war will resume. When asked if he was prepared to extend the ceasefire agreement if no deal is made by the time the ceasefire expires on Wednesday, Trump replied, "Maybe I won't extend the ceasefire. But the blockade will continue. So, the blockade remains in place, and unfortunately, we will have to start dropping bombs again," Trump warned.

  • Chinese Ship Trapped in Strait of Hormuz Informs Crew to Prepare for Departure

    On April 18, according to Yicai, around 4 PM local time on the 17th, the Chinese ship trapped in the Strait of Hormuz has informed its crew to 'prepare for departure.' According to CCTV, on the afternoon of the 17th, Iranian Foreign Minister Amir-Abdollahian stated on social media that, based on the ceasefire agreement in Lebanon, all commercial vessels are allowed to pass through the Strait of Hormuz completely open during the remaining time of the ceasefire, following the coordinated routes announced by Iranian ports and maritime organizations.

  • DeepSeek Seeks Over $300 Million in First Round of External Funding

    According to The Information, DeepSeek is seeking over $300 million in its first round of external funding, with a valuation exceeding $10 billion.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,024.64, with a 24-hour increase of 5.63%. The market is highly volatile, so please ensure proper risk management.

  • BTC Surpasses $77,000

    Market data shows that BTC has surpassed $77,000, currently priced at $77,022.24, with a 24-hour increase of 3.42%. Due to significant market fluctuations, please ensure proper risk management.