Meter Passport Unbacked Mint Exploit
An attacker abused a block-validation flaw in Meter to mint unbacked wrapped MTRG through the Meter Passport bridge, dumping about $2.3 million of it on PancakeSwap and crashing both MTR and MTRG.
Vuln-watch · relayed from a public source; see Source & attribution below
Summary
An attacker abused a block-validation flaw in Meter to mint unbacked wrapped MTRG through the Meter Passport bridge, dumping about $2.3 million of it on PancakeSwap and crashing both MTR and MTRG.
Incident
- Victim: Meter
- Date (UTC): 2026-09-23
- Estimated loss: $2.3M
- Chain(s): Meter, BNB Chain
- Attack type: bridge exploit
- Funds status: stolen
Recommended actions
- Revoke token approvals granted to Meter contracts until the project confirms they are safe
- Integrators: pause or delist affected assets and monitor for attacker fund movements
- Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only
Source & attribution
Full analysis on Blockchain Breaches, 0xCERT's incident archive: https://www.blockchainbreaches.com/en/breaches/meter-2026. Primary sources: https://protos.com/defi-hack-attack-three-exploits-snatch-11m-in-a-single-day/ ; https://www.cryptotimes.io/2026/09/24/meter-passport-exploit-reportedly-mints-2-3-million-in-unbacked-mtrg/ ; https://phemex.com/news/article/meter-protocol-under-active-exploit-on-bnb-chain-as-attacker-mints-23m-in-unbacked-tokens-97771.
References
- https://www.blockchainbreaches.com/en/breaches/meter-2026
- https://protos.com/defi-hack-attack-three-exploits-snatch-11m-in-a-single-day/
- https://www.cryptotimes.io/2026/09/24/meter-passport-exploit-reportedly-mints-2-3-million-in-unbacked-mtrg/
- https://phemex.com/news/article/meter-protocol-under-active-exploit-on-bnb-chain-as-attacker-mints-23m-in-unbacked-tokens-97771
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-23 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0172/signed.txt | gpg --verify